CVE-2025-40736: Critical severity Siemens SINEC NMS vulnerability
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative credentials. This could allow an unauthenticated attacker to reset the superadmin password and gain full control of the application (ZDI-CAN-26569).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40736?
CVE-2025-40736 is considered a critical vulnerability due to the potential for unauthorized administrative access.
How do I fix CVE-2025-40736?
To mitigate CVE-2025-40736, update SINEC NMS to version 4.0 or later as soon as possible.
What is the risk of not addressing CVE-2025-40736?
Failure to address CVE-2025-40736 may allow attackers to reset admin passwords and gain full control over the SINEC NMS application.
Who is affected by CVE-2025-40736?
All versions of Siemens SINEC NMS prior to version 4.0 are affected by CVE-2025-40736.
Is there an exploit available for CVE-2025-40736?
Yes, CVE-2025-40736 can be exploited remotely by an unauthorized attacker to compromise administrative credentials.