CVE-2025-40807: Medium severity Gridscale Gridscale X Prepay vulnerability
Published Dec 9, 2025
·Updated
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could allow an authenticated but already locked-out user to establish still valid user sessions.
Affected Software
2 affected components
Gridscale Gridscale X Prepay<4.2.1
Siemens Gridscale X Prepay<4.2.1
Event History
Dec 9, 2025
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40807?
CVE-2025-40807 is considered a high severity vulnerability due to its potential for session hijacking.
2
How do I fix CVE-2025-40807?
To fix CVE-2025-40807, upgrade Gridscale X Prepay to version 4.2.1 or later.
3
What are the risks associated with CVE-2025-40807?
The risks include the potential for unauthorized access as locked-out users may regain access through token replay.
4
Who is affected by CVE-2025-40807?
All users of Gridscale X Prepay versions prior to 4.2.1 are affected by CVE-2025-40807.
5
What types of attacks can CVE-2025-40807 enable?
CVE-2025-40807 can enable capture-replay attacks, allowing attackers to reuse authentication tokens.