CVE-2025-41648CRITICAL 9.8EPSS p48.1%
CVE-2025-41648CVE-2025-41648
Description
An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.70% probability of exploitation · percentile 48.1% · 2026-06-18T12:00:27Z |
| Published | 2025-07-01 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Type Conversion or Castcwe-704 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.