Remote Access Vulnerability in IndustrialPI by VDE
CVE-2025-41648
9.8CRITICAL
What is CVE-2025-41648?
An unauthenticated remote attacker can exploit a security flaw in IndustrialPI, enabling them to bypass authentication mechanisms. This vulnerability allows unauthorized users to gain access to the web application, granting them the ability to modify and manipulate all device settings without proper authorization, posing significant risks to system integrity and operational security.
Affected Version(s)
IndustrialPI 4 with IndustrialPI webstatus 0 < 2.4.6