CVE-2025-41720 describes a vulnerability where a low-privileged remote attacker can upload arbitrary data to an affected device by disguising it as a PNG file, due to insufficient file extension validation by the webserver API. This medium-severity vulnerability (CVSS 4.3) has a low attack complexity and requires low privileges, potentially leading to limited integrity impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sauter | EY-Modulo 5 Ecos 5 Ecos504/505 | >= 0.0, < Firmware v6.0CNA affecteddefault unaffected | |
| Sauter | EY-Modulo 5 Modu 5 Modu524 | >= 0.0, < Firmware v6.0CNA affecteddefault unaffected | |
| Sauter | EY-Modulo 5 Modu 5 Modu525 | >= 0.0, < Firmware v6.0CNA affecteddefault unaffected | |
| Sauter | Modulo 6 Devices Modu612-LC | >= 0.0.0, < Firmware v3.2.0CNA affecteddefault unaffected | |
| Sauter | Modulo 6 Devices Modu660-AS | >= 0.0.0, < Firmware v3.2.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.