PT-2025-25306 · Sick Ag+1 · Sick Media Server+1

Published

2025-06-12

·

Updated

2026-01-29

·

CVE-2025-49182

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description The issue allows an attacker to gain full access to the application due to login credentials for the admin user and the property configuration password being stored in files within the source code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-49182

Affected Products

Sick Media Server
Mediaserver