{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-26411",
        "assignerOrgId": "551230f0-3615-47bd-b7cc-93e92e730bbf",
        "state": "PUBLISHED",
        "assignerShortName": "SEC-VLab",
        "dateReserved": "2025-02-10T07:48:38.352Z",
        "datePublished": "2025-02-11T09:21:16.571Z",
        "dateUpdated": "2025-11-03T21:12:54.561Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unknown",
                    "product": "Wattsense Bridge",
                    "vendor": "Wattsense",
                    "versions": [
                        {
                            "lessThan": "6.1.0",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Constantin Schieber-Knöbl | SEC Consult Vulnerability Lab"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Stefan Schweighofer | SEC Consult Vulnerability Lab"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Steffen Robertz | SEC Consult Vulnerability Lab"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface&nbsp;to be able to conduct this attack. This issue is fixed in recent firmware versions BSP &gt;= 6.1.0."
                        }
                    ],
                    "value": "An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct this attack. This issue is fixed in recent firmware versions BSP >= 6.1.0."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-175",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-175 Code Inclusion"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-434",
                            "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "551230f0-3615-47bd-b7cc-93e92e730bbf",
                "shortName": "SEC-VLab",
                "dateUpdated": "2025-02-11T09:21:16.571Z"
            },
            "references": [
                {
                    "tags": [
                        "third-party-advisory"
                    ],
                    "url": "https://r.sec-consult.com/wattsense"
                },
                {
                    "tags": [
                        "release-notes"
                    ],
                    "url": "https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "This issue is fixed in recent firmware versions BSP &gt;= 6.1.0."
                        }
                    ],
                    "value": "This issue is fixed in recent firmware versions BSP >= 6.1.0."
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "title": "Authenticated Arbitrary Python File Upload via Plugin Manager",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 8.8,
                            "attackVector": "NETWORK",
                            "baseSeverity": "HIGH",
                            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "LOW",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-02-11T14:33:44.192168Z",
                                "id": "CVE-2025-26411",
                                "options": [
                                    {
                                        "Exploitation": "poc"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-03-14T17:16:02.468Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "http://seclists.org/fulldisclosure/2025/Feb/9"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T21:12:54.561Z"
                }
            }
        ]
    }
}