An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://certvde.com/en/advisories/VDE-2025-045 |
![]() ![]() |
History
Tue, 01 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. | |
Title | Pilz: Missing Authentication in Node-RED integration | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-07-01T08:10:06.208Z
Updated: 2025-07-01T14:32:08.516Z
Reserved: 2025-04-16T11:17:48.306Z
Link: CVE-2025-41656

Updated: 2025-07-01T14:32:03.656Z

Status : Received
Published: 2025-07-01T08:15:24.443
Modified: 2025-07-01T08:15:24.443
Link: CVE-2025-41656

No data.