Web Interface Vulnerability in ctrlX OS by Bosch
CVE-2025-48862
7.1HIGH
What is CVE-2025-48862?
The web interface of ctrlX OS contains ambiguous wording that may confuse users into thinking that backup files are encrypted when a password is set. However, it is crucial to note that only the private key within the backup is encrypted, while the backup file itself remains unencrypted. This misrepresentation can expose sensitive data if users assume their backups are securely protected.
Affected Version(s)
ctrlX OS - Setup 1.20.0 <= 1.20.1
ctrlX OS - Setup 2.6.0 <= 2.6.1
ctrlX OS - Setup 3.6.0 <= 3.6.2
