CVE-2025-41710 PUBLISHED

Use of Hard-coded Credentials in power analyzer

Assigner: CERTVDE
Reserved: 16.04.2025 Published: 10.03.2026 Updated: 10.03.2026

An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 6.5

Product Status

Vendor Janitza
Product UMG 96RM-E 24V(5222063)
Versions Default: unaffected
  • affected from 0.0 to 3.13 (incl.)
Vendor Janitza
Product UMG 96RM-E 230V(5222062)
Versions Default: unaffected
  • affected from 0.0 to 3.13 (incl.)
Vendor Weidmueller
Product ENERGY METER 750-230 (2540910000)
Versions Default: unaffected
  • affected from 0.0 to 3.13 (incl.)
Vendor Weidmueller
Product ENERGY METER 750-24 (2540900000)
Versions Default: unaffected
  • affected from 0.0 to 3.13 (incl.)

Credits

  • Deutsche Telekom Security (DT Security) reporter

References

Problem Types

  • CWE-798 Use of Hard-coded Credentials CWE