PT-2025-15389 · Unknown · Senron 7Kt Pac1260 Data Manager

Published

2025-04-08

·

Updated

2025-04-08

·

CVE-2024-41791

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SENRON 7KT PAC1260 Data Manager (all versions)
Description: A security issue has been identified where the web interface of affected devices does not authenticate report creation requests. This could allow an unauthenticated remote attacker to read or clear the log files on the device, reset the device, or set the date and time.
Recommendations: For all versions, consider disabling the web interface until a patch is available to prevent unauthorized access. Restrict access to the device's configuration settings to minimize the risk of exploitation. Avoid using the device's web interface for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04627
CVE-2024-41791

Affected Products

Senron 7Kt Pac1260 Data Manager