2026-03-10 8:26CVE-2025-41710CERTVDE
PUBLISHED5.2CWE-798

Use of Hard-coded Credentials in power analyzer

An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.

Problem type

Affected products

Janitza

UMG 96RM-E 24V(5222063)

<= 3.13 - AFFECTED

UMG 96RM-E 230V(5222062)

<= 3.13 - AFFECTED

Weidmueller

ENERGY METER 750-230 (2540910000)

<= 3.13 - AFFECTED

ENERGY METER 750-24 (2540900000)

<= 3.13 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2025-41710
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2025-41710",
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "dateUpdated": "2026-03-10T08:26:30.909Z",
    "dateReserved": "2025-04-16T11:17:48.311Z",
    "datePublished": "2026-03-10T08:26:30.909Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE",
        "dateUpdated": "2026-03-10T08:26:30.909Z"
      },
      "title": "Use of Hard-coded Credentials in power analyzer",
      "descriptions": [
        {
          "lang": "en",
          "value": "An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<span style=\"background-color: rgb(255, 255, 255);\">An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.</span><br>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 24V(5222063)",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0.0",
              "status": "affected",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ]
        },
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 230V(5222062)",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0.0",
              "status": "affected",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ]
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-230 (2540910000)",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0.0",
              "status": "affected",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ]
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-24 (2540900000)",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0.0",
              "status": "affected",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-798 Use of Hard-coded Credentials",
              "cweId": "CWE-798",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://certvde.com/en/advisories/VDE-2025-079/",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://certvde.com/en/advisories/VDE-2025-096/",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-079.json",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-096.json",
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Deutsche Telekom Security (DT Security)",
          "user": "00000000-0000-4000-9000-000000000000",
          "type": "reporter"
        }
      ]
    }
  }
}