CVE 7.2 HIGH

RACOM M!DGE2 Privilege Escalation via SDK Testing Endpoint_CVE-2025-36729

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

Basic Information

ID CVE-2025-36729
Source tenable
Published Aug 26, 2025 at 16:26

Affected Product

Vendor RACOM
Product M!DGE2
Version 4.0
Affected Versions RACOM M!DGE2 4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.