CVE-2025-25728
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
28/02/2025
Last modified:
19/03/2025
Description
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



