VulnerabilityDeferred
CVE-2025-11155
Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
MEDIUM 6.8EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
- CVSS 4.0
- 6.8 MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-261
- Source
- 50b5080a-775f-442e-83b5-926b5ca517b6
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.