VDB

CVE-2025-26390

CVE-2025-26390 PUBLISHED CVSS 9.800000190734863 CRITICAL

A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and authenticate as Administrator user.

EPSS 0.64% · 48.8th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.64%
48.8th percentile

Affected Products

VendorProductVersions
SiemensOZW7720
siemensozw772_firmware0
SiemensOZW6720
siemensozw672_firmware0

Timeline

  • Feb 7, 2025 CVE ID Reserved
  • May 13, 2025 EPSS Score
  • May 13, 2025 Coalition ESS Score
  • May 13, 2025 CVE Published
  • May 13, 2025 CVE Updated
  • May 14, 2025 Coalition ESS Score
  • May 15, 2025 PoC Published
  • May 25, 2025 EPSS Score
  • May 26, 2025 Coalition ESS Score
  • Jun 6, 2025 EPSS Score
  • Jun 18, 2025 EPSS Score
  • Jun 30, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›