PT-2025-34793 · Racom · M!Dge2

Derrie Sutton

+1

·

Published

2025-08-26

·

Updated

2025-08-26

·

CVE-2025-36729

CVSS v3.1
7.2
VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-36729

Affected Products

M!Dge2