CVE-2025-40805: Critical severity vulnerability
Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40805?
The severity of CVE-2025-40805 is classified as critical with a score of 10.
How do I fix CVE-2025-40805?
To fix CVE-2025-40805, apply the latest security patches and updates provided by the device vendor.
What are the potential impacts of CVE-2025-40805?
CVE-2025-40805 could allow an unauthenticated remote attacker to impersonate a legitimate user, leading to unauthorized access.
Could CVE-2025-40805 affect my organization's data?
Yes, if exploited, CVE-2025-40805 could result in the compromise of sensitive data and user accounts.
What types of devices are affected by CVE-2025-40805?
CVE-2025-40805 affects devices that do not properly enforce user authentication on specific API endpoints.