CVE-2025-40755: SQL Injection
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SINEC NMSto a version that resolves this vulnerability.Fixed in V4.0 SP1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40755?
CVE-2025-40755 is categorized as a high-severity vulnerability due to its potential for SQL injection and privilege escalation.
How do I fix CVE-2025-40755?
To fix CVE-2025-40755, upgrade SINEC NMS to version 4.0 SP1 or later.
What type of vulnerability is CVE-2025-40755?
CVE-2025-40755 is identified as an SQL injection vulnerability affecting the getTotalAndFilterCounts endpoint.
Who can exploit CVE-2025-40755?
An authenticated low privileged attacker can exploit CVE-2025-40755 to insert malicious data.
What applications are affected by CVE-2025-40755?
CVE-2025-40755 affects all versions of SINEC NMS prior to version 4.0 SP1.