Weak Password Generation in WebUI of an Affected Product from Vendor
CVE-2025-41692

6.8MEDIUM

Key Information:

Vendor
CVE Published:
9 December 2025

What is CVE-2025-41692?

A vulnerability exists in the web-based user interface of the affected product, allowing a remote attacker with administrator privileges to brute-force the root and user passwords. The issue is caused by the inadequate algorithm used for password generation, which diminishes the strength of the credentials and exposes the system to unauthorized access attempts. Organizations utilizing this product should take immediate measures to enhance password policies and implement stronger authentication methods.

Affected Version(s)

FL NAT 2008 0.0.0 < 3.50

FL NAT 2208 0.0.0 < 3.50

FL NAT 2304-2GC-2SFP 0.0.0 < 3.50

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube
.
CVE-2025-41692 : Weak Password Generation in WebUI of an Affected Product from Vendor