{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-25265","assignerOrgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","state":"PUBLISHED","assignerShortName":"CERTVDE","dateReserved":"2025-02-06T12:30:08.318Z","datePublished":"2025-06-16T09:46:13.998Z","dateUpdated":"2025-11-21T11:38:18.852Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"WAGO CC100 0751-9x01","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"CC100 0751-9x01","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PFC100 G1 0750-810x/xxxx-xxxx","vendor":"WAGO","versions":[{"lessThan":"3.10.11 (FW22 Patch 2)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PFC100 G2 0750-811x-xxxx-xxxx","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PFC100 G2 0750-811x-xxxx-xxxx","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PFC200 G1 750-820x-xxx-xxx","vendor":"WAGO","versions":[{"lessThan":"3.10.11 (FW22 Patch 2)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PFC200 G2 750-821x-xxx-xxx","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PFC200 G2 750-821x-xxx-xxx","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-420x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-420x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-430x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-430x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-520x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-520x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-530x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-530x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-620x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-620x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-630x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"TP600 0762-630x/8000-000x","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Edge Controller 0752-8303/8000-0002","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (FW29)","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Edge Controller 0752-8303/8000-0002","vendor":"WAGO","versions":[{"lessThan":"04.07.01 (70)","status":"affected","version":"0.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure.<br>"}],"value":"A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","shortName":"CERTVDE","dateUpdated":"2025-11-21T11:38:18.852Z"},"references":[{"url":"https://certvde.com/en/advisories/VDE-2025-018/"}],"source":{"advisory":"VDE-2025-018","defect":["CERT@VDE#641748"],"discovery":"UNKNOWN"},"title":"Unauthenticated File Read via Web Interface","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-06-16T18:12:43.011626Z","id":"CVE-2025-25265","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-16T18:13:49.552Z"}}]}}