CVE-2025-2859
Severity CVSS v4.0:
MEDIUM
Type:
CWE-287
Authentication Issues
Publication date:
28/03/2025
Last modified:
10/10/2025
Description
An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



