CVE-2025-40765: Critical severity TeleControl Server Basic vulnerability
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40765?
CVE-2025-40765 has been classified as a high severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2025-40765?
To fix CVE-2025-40765, update TeleControl Server Basic to version 3.1.2.3 or later.
What type of vulnerability is CVE-2025-40765?
CVE-2025-40765 is an information disclosure vulnerability affecting certain versions of TeleControl Server Basic.
Who is affected by CVE-2025-40765?
All users of TeleControl Server Basic versions from 3.1.2.2 to 3.1.2.3 are affected by CVE-2025-40765.
Can I exploit CVE-2025-40765 remotely?
Yes, CVE-2025-40765 can be exploited remotely by an unauthenticated attacker to obtain user password hashes.