VDB

CVE-2025-40736

CVE-2025-40736 PUBLISHED CVSS 9.800000190734863 CRITICAL

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative credentials. This could allow an unauthenticated attacker to reset the superadmin password and gain full control of the application (ZDI-CAN-26569).

EPSS 0.48% · 65.5th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.48%
65.5th percentile

Affected Products

VendorProductVersions
siemenssinec_nms0
SiemensSINEC NMS0

Timeline

  • Jul 8, 2025 EPSS Score
  • Jul 8, 2025 Coalition ESS Score
  • Jul 8, 2025 PoC Published
  • Jul 8, 2025 CVE Published
  • Jul 8, 2025 PoC Published
  • Jul 8, 2025 PoC Published
  • Jul 9, 2025 Coalition ESS Score
  • Jul 9, 2025 PoC Published
  • Jul 10, 2025 PoC Published
  • Jul 18, 2025 EPSS Score
  • Jul 27, 2025 EPSS Score
  • Aug 6, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›