CVE-2025-48861
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
14/08/2025
Last modified:
14/08/2025
Description
A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to access and extract internal application data, including potential debug logs and the version of installed apps.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



