PT-2025-43026 · Sauter · Ey-Modulo 5 Ecos 5 Ecos504/505+5

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-41720

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-41720

Affected Products

Ey-Modulo 5 Ecos 5 Ecos504/505
Ey-Modulo 5 Modu 5 Modu524
Ey-Modulo 5 Modu 5 Modu525
Modulo 6 Devices Modu612-Lc
Modulo 6 Devices Modu660-As
Modulo 6 Devices Modu680-As