PT-2026-39979 · Unknown · Blueplanet 92.0 Tl3+29
Published
2026-05-12
·
Updated
2026-05-12
·
CVE-2025-40946
CVSS v3.1
8.3
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
blueplanet 100 NX3 M8 (affected versions not specified)
blueplanet 100 TL3 GEN2 versions prior to V6.1.4.9
blueplanet 105 TL3 (affected versions not specified)
blueplanet 105 TL3 GEN2 versions prior to V6.1.4.9
blueplanet 110 TL3 (affected versions not specified)
blueplanet 125 NX3 M11 (affected versions not specified)
blueplanet 125 TL3 (affected versions not specified)
blueplanet 125 TL3 GEN2 versions prior to V6.1.4.9
blueplanet 137 TL3 (affected versions not specified)
blueplanet 150 TL3 (affected versions not specified)
blueplanet 150 TL3 GEN2 versions prior to V6.1.4.9
blueplanet 155 TL3 (affected versions not specified)
blueplanet 155 TL3 GEN2 versions prior to V6.1.4.9
blueplanet 165 TL3 (affected versions not specified)
blueplanet 165 TL3 GEN2 versions prior to V6.1.4.9
blueplanet 25.0 NX3-33.0 NX3 (affected versions not specified)
blueplanet 3.0 NX3-20.0 NX3 (affected versions not specified)
blueplanet 3.0 TL3-60.0 TL3 (affected versions not specified)
blueplanet 3.0-5.0 NX1 (affected versions not specified)
blueplanet 360 NX3 M6 (affected versions not specified)
blueplanet 50.0 NX3-60.0 NX3 (affected versions not specified)
blueplanet 87.0 TL3 (affected versions not specified)
blueplanet 87.0 TL3 GEN2 versions prior to V6.1.4.9
blueplanet 92.0 TL3 (affected versions not specified)
blueplanet 92.0 TL3 GEN2 versions prior to V6.1.4.9
blueplanet gridsafe 110 TL3-S versions prior to V3.91
blueplanet gridsafe 137 TL3-S versions prior to V3.91
blueplanet gridsafe 92.0 TL3-S versions prior to V3.91
blueplanet hybrid 10.0 TL3 (affected versions not specified)
blueplanet hybrid 6.0 NH3-12.0 NH3 (affected versions not specified)
Description
A weakness in the CRC16-based algorithm used to generate Technical Service credentials allows an attacker to derive these credentials from the device serial number. This could lead to unauthorized remote administrative access.
Recommendations
Update blueplanet 100 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet 105 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet 125 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet 150 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet 155 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet 165 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet 87.0 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet 92.0 TL3 GEN2 to version V6.1.4.9 or later.
Update blueplanet gridsafe 110 TL3-S to version V3.91 or later.
Update blueplanet gridsafe 137 TL3-S to version V3.91 or later.
Update blueplanet gridsafe 92.0 TL3-S to version V3.91 or later.
At the moment, there is no information about a newer version that contains a fix for the other affected versions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blueplanet 100 Nx3 M8
Blueplanet 100 Tl3 Gen2
Blueplanet 105 Tl3
Blueplanet 105 Tl3 Gen2
Blueplanet 110 Tl3
Blueplanet 125 Nx3 M11
Blueplanet 125 Tl3
Blueplanet 125 Tl3 Gen2
Blueplanet 137 Tl3
Blueplanet 150 Tl3
Blueplanet 150 Tl3 Gen2
Blueplanet 155 Tl3
Blueplanet 155 Tl3 Gen2
Blueplanet 165 Tl3
Blueplanet 165 Tl3 Gen2
Blueplanet 25.0 Nx3-33.0 Nx3
Blueplanet 3.0 Nx3-20.0 Nx3
Blueplanet 3.0 Tl3-60.0 Tl3
Blueplanet 3.0-5.0 Nx1
Blueplanet 360 Nx3 M6
Blueplanet 50.0 Nx3-60.0 Nx3
Blueplanet 87.0 Tl3
Blueplanet 87.0 Tl3 Gen2
Blueplanet 92.0 Tl3
Blueplanet 92.0 Tl3 Gen2
Blueplanet Gridsafe 110 Tl3-S
Blueplanet Gridsafe 137 Tl3-S
Blueplanet Gridsafe 92.0 Tl3-S
Blueplanet Hybrid 10.0 Tl3
Blueplanet Hybrid 6.0 Nh3-12.0 Nh3