PT-2025-33295 · Espec North America · Espec North America Web Controller 3

Published

2025-08-14

·

Updated

2025-08-16

·

CVE-2025-27846

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: ESPEC North America Web Controller 3 versions prior to 3.3.8
Description: An attacker with physical access can gain elevated privileges due to the lack of protection for GRUB and the BIOS.
Recommendations: Update ESPEC North America Web Controller 3 to version 3.3.8 or later.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-27846

Affected Products

Espec North America Web Controller 3