PT-2025-43026 · Sauter · Ey-Modulo 5 Ecos 5 Ecos504/505+5
Published
2025-10-22
·
Updated
2025-10-22
·
CVE-2025-41720
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ey-Modulo 5 Ecos 5 Ecos504/505
Ey-Modulo 5 Modu 5 Modu524
Ey-Modulo 5 Modu 5 Modu525
Modulo 6 Devices Modu612-Lc
Modulo 6 Devices Modu660-As
Modulo 6 Devices Modu680-As