Security Flaw in Device Management for Non-Primary Admin Users by Affected Vendor
CVE-2025-36729

7.2HIGH

Key Information:

Vendor

Racom

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-36729?

This vulnerability allows non-primary administrator users with admin rights on the web interface to access and display sensitive device configuration information, including the master admin password. Furthermore, it enables these users to escalate their privileges by granting themselves shell access with root privileges, posing a significant security risk by potentially compromising the entire system.

Affected Version(s)

M!DGE2 4.0 <= 4.6.40.106

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Derrie Sutton
Giulio Lyons
.
CVE-2025-36729 : Security Flaw in Device Management for Non-Primary Admin Users by Affected Vendor