CVE-2025-41771

Severity CVSS v4.0:
MEDIUM
Type:
CWE-89 SQL Injection
Publication date:
12/08/2026
Last modified:
12/08/2026

Description

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.