CVE 7.4 HIGH

Cleartext Transmission of Sensitive Data via Insecure HTTP Web Interface_CVE-2025-41708

7.4 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.

Basic Information

ID CVE-2025-41708
Source CERTVDE
Published Sep 8, 2025 at 06:38

Affected Product

Vendor Bender
Product CC612
Version 0.0.0
Affected Versions Bender CC612 0.0.0
Bender CC613 0.0.0
Bender ICC15xx 0.0.0
Bender ICC16xx 0.0.0
Bender ICC13xx 0.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.