CVE-2025-41378
Severity CVSS v4.0:
MEDIUM
Type:
CWE-20
Input Validation
Publication date:
23/05/2025
Last modified:
23/05/2025
Description
The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM



