216.73.216.233

CVE-2025-40805

· Published 13/01/2026 10:15 · Modified 13/01/2026 14:03

Labels: CVE-2025-40805 2026-01-13CVE-2025-40805CWE-639[email protected]

Essential information

Published
13/01/2026 10:15
Modified
13/01/2026 14:03
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
siemens / device cpe:2.3:a:siemens:device:*:*:*:*:*:*:*:*

References