PT-2025-39104 · Unknown · Vitogate 300
Souvik Kandar
·
Published
2025-09-23
·
Updated
2025-09-23
·
CVE-2025-9495
CVSS v4.0
8.7
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vitogate 300 (affected versions not specified)
Description
The web interface does not properly enforce server-side authentication, relying instead on frontend-based authentication controls. This allows an attacker to bypass login restrictions by modifying HTML elements in the browser’s developer tools. By removing specific UI elements, an attacker can reveal the hidden administration menu, gaining full control over the device. The
HTML elements can be modified to bypass login restrictions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vitogate 300