PT-2025-28394 · Sinec Nms · Sinec Nms

Published

2025-07-08

·

Updated

2025-07-09

·

CVE-2025-40736

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SINEC NMS versions prior to V4.0
Description: A vulnerability has been identified in the affected application, which exposes an endpoint that allows unauthorized modification of administrative credentials. This could allow an unauthenticated attacker to reset the superadmin password and gain full control of the application.
Recommendations: For versions prior to V4.0, update to version V4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the exposed endpoint to minimize the risk of exploitation. Avoid using the affected application until the issue is resolved.

Fix

RCE

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-08268
CVE-2025-40736
ZDI-25-574

Affected Products

Sinec Nms