CVE-2025-41771
Severity CVSS v4.0:
MEDIUM
Type:
CWE-89
SQL Injection
Publication date:
12/08/2026
Last modified:
12/08/2026
Description
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM



