External Control Vulnerability in Danfoss AK-SM8xxA Series Products
CVE-2025-41452

6.8MEDIUM

Key Information:

Vendor

Danfoss

Vendor
CVE Published:
22 August 2025

What is CVE-2025-41452?

A vulnerability has been identified in the Danfoss AK-SM8xxA Series that affects the configuration settings of the system web interface. This post-authenticated external control vulnerability could potentially allow attackers to induce a denial of service by exploiting improper handling of exceptional conditions. Users are advised to update to version 4.3.1 or later to mitigate this risk.

Affected Version(s)

AK-SM8xxA Series 0 < 4.3.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-41452 : External Control Vulnerability in Danfoss AK-SM8xxA Series Products