CVE-2025-11155EPSS p8.1%
CVE-2025-11155CVE-2025-11155
Description
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
Scoring
| EPSS | 0.19% probability of exploitation · percentile 8.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |