Remote Code Execution Vulnerability in Janitza and Weidmuller Web Server Products
CVE-2025-41712

6.5MEDIUM

What is CVE-2025-41712?

An unauthenticated remote attacker can exploit a vulnerability in specific Janitza and Weidmuller web server products by tricking a user into uploading a manipulated HTML file. This inadequate permission assignment on the web server can lead to unauthorized access to sensitive information on the device.

Affected Version(s)

ENERGY METER 750-230 (2540910000) 0.0 <= 3.13

ENERGY METER 750-24 (2540900000) 0.0 <= 3.13

UMG 96RM-E 230V(5222062) 0.0 <= 3.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deutsche Telekom Security (DT Security)
.