CVE-2025-8393
Severity CVSS v4.0:
HIGH
Type:
CWE-295
Improper Certificate Validation
Publication date:
08/08/2025
Last modified:
08/08/2025
Description
A TLS vulnerability exists in the phone application used to manage a <br />
connected device. The phone application accepts self-signed certificates<br />
when establishing TLS communication which may result in <br />
man-in-the-middle attacks on untrusted networks. Captured communications<br />
may include user credentials and sensitive session tokens.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
7.30
Severity 3.x
HIGH



