An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-03-28 14:15
Updated : 2025-10-10 16:40
NVD link : CVE-2025-2859
Mitre link : CVE-2025-2859
CVE.ORG link : CVE-2025-2859
JSON object : View
Products Affected
arteche
- satech_bcu
- satech_bcu_firmware
CWE
CWE-287
Improper Authentication
