PT-2025-13517 · Arteche · Satech Bcu+1

Aarón Flecha

·

Published

2025-03-28

·

Updated

2025-04-04

·

CVE-2025-2859

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description An attacker with access to the network where the vulnerable device is located could capture traffic and obtain cookies from the user, allowing them to steal a user's active session and make changes to the device via the web, depending on the privileges obtained by the user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-2859

Affected Products

Satech Bcu
Satech Bcu Firmware