CVE-2025-3200 describes a critical vulnerability where an unauthenticated remote attacker can intercept and manipulate encrypted communications due to the use of insecure TLS 1.0 and 1.1 protocols in Wiesemann & Theis Com-Server firmware versions prior to 1.60. This vulnerability carries a CVSS score of 9.1 (CRITICAL), indicating a high-impact attack with low complexity and no user interaction required, potentially leading to complete confidentiality and integrity compromise. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wiesemann & Theis | Com-Server 20mA | >= 0.0.0, < 1.60CNA affecteddefault unaffected | |
| Wiesemann & Theis | Com-Server OEM | >= 0.0.0, < 1.60CNA affecteddefault unaffected | |
| Wiesemann & Theis | Com-Server PoE 3x Isolated | >= 0.0.0, < 1.60CNA affecteddefault unaffected | |
| Wiesemann & Theis | Com-Server UL | >= 0.0.0, < 1.60CNA affecteddefault unaffected | |
| Wiesemann & Theis | Com-Server++ | >= 0.0.0, < 1.60CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.