Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://certvde.com/de/advisories/VDE-2025-084 |
![]() ![]() |
History
Mon, 15 Sep 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bender
Bender cc612 Bender cc613 Bender icc13xx Bender icc15xx Bender icc16xx |
|
Vendors & Products |
Bender
Bender cc612 Bender cc613 Bender icc13xx Bender icc15xx Bender icc16xx |
Mon, 08 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 08 Sep 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission. | |
Title | Cleartext Transmission of Sensitive Data via Insecure HTTP Web Interface | |
Weaknesses | CWE-319 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-09-08T06:38:50.386Z
Updated: 2025-09-08T18:04:06.675Z
Reserved: 2025-04-16T11:17:48.311Z
Link: CVE-2025-41708

Updated: 2025-09-08T18:03:10.228Z

Status : Awaiting Analysis
Published: 2025-09-08T07:15:36.523
Modified: 2025-09-08T16:25:38.810
Link: CVE-2025-41708

No data.