PT-2026-2205 · Unknown · Vwebserver

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2026-22543

CVSS v4.0

6.9

Medium

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions (affected versions not specified)
Description The credentials needed to access the device’s web server are transmitted in base64 within the HTTP headers. Base64 encoding is not a secure encryption method, allowing an attacker intercepting the web request during login to potentially obtain the credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-22543

Affected Products

Vwebserver