CVE-2025-36535
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
21/05/2025
Last modified:
21/05/2025
Description
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.
Impact
Base Score 4.0
10.00
Severity 4.0
CRITICAL
Base Score 3.x
10.00
Severity 3.x
CRITICAL



