PT-2026-28307 · Microchip · Microchip Timeprovider 4100
Andrea Sindoni
+8
·
Published
2026-03-28
·
Updated
2026-03-28
·
CVE-2025-9497
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microchip Time Provider 4100 versions prior to 2.5.0
Description
A use of hard-coded credentials issue exists in Microchip Time Provider 4100, potentially allowing for malicious manual software updates.
Recommendations
Update Microchip Time Provider 4100 to version 2.5.0 or later.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microchip Timeprovider 4100