Cleartext Password Storage Vulnerability in Bosscomm IF740 Firmware
CVE-2025-25727

6.2MEDIUM

Key Information:

Vendor

Bosscomm

Status
Vendor
CVE Published:
28 February 2025

What is CVE-2025-25727?

The Bosscomm IF740 firmware has been found to store sensitive passwords in cleartext, posing significant security risks. Versions v11001.7078 and v11001.0000, along with System versions 6.25 and 6.00, are affected by this vulnerability. This flaw enables potential unauthorized access to sensitive data, as attackers could easily intercept and exploit these plaintext passwords. Users of the affected firmware and system versions should consider immediate upgrades to mitigate potential security breaches.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.