PT-2026-28307 · Microchip · Microchip Timeprovider 4100

Andrea Sindoni

+8

·

Published

2026-03-28

·

Updated

2026-03-28

·

CVE-2025-9497

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microchip Time Provider 4100 versions prior to 2.5.0
Description A use of hard-coded credentials issue exists in Microchip Time Provider 4100, potentially allowing for malicious manual software updates.
Recommendations Update Microchip Time Provider 4100 to version 2.5.0 or later.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9497

Affected Products

Microchip Timeprovider 4100