PT-2025-28394 · Sinec Nms · Sinec Nms
Published
2025-07-08
·
Updated
2025-07-09
·
CVE-2025-40736
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SINEC NMS versions prior to V4.0
Description:
A vulnerability has been identified in the affected application, which exposes an endpoint that allows unauthorized modification of administrative credentials. This could allow an unauthenticated attacker to reset the superadmin password and gain full control of the application.
Recommendations:
For versions prior to V4.0, update to version V4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the exposed endpoint to minimize the risk of exploitation. Avoid using the affected application until the issue is resolved.
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinec Nms