AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2025-41771

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An authenticated attacker with low privileges can exploit a SQL injection vulnerability in the controller's web interface, allowing access to a SQLite database used for storing notification messages. While the impact is limited to the notification functionality, organizations using this system should prioritize remediation to prevent potential unauthorized access to sensitive information. Systems with low privilege user access should be particularly vigilant in addressing this issue.

CVE
CVE-2025-41771
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.