CVE-2025-40838: Ericsson Indoor Connect 8855 - Insufficiently Protected Credentials Vulnerability
Published Sep 25, 2025
·Updated
Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.
Affected Software
3 affected components
Ericsson Indoor Connect 8855
All of the following
Ericsson Indoor Connect 8855 Firmware<2025.q2
Ericsson Indoor Connect 8855
Event History
Sep 25, 2025
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40838?
CVE-2025-40838 is considered a high severity vulnerability due to the potential for unauthorized disclosure of user accounts.
2
How do I fix CVE-2025-40838?
To remediate CVE-2025-40838, update the Ericsson Indoor Connect 8855 to the latest version provided by Ericsson.
3
What type of vulnerability is CVE-2025-40838?
CVE-2025-40838 is a server-side security bypass vulnerability affecting the client interface.
4
What can attackers do by exploiting CVE-2025-40838?
Exploiting CVE-2025-40838 can allow attackers to access and disclose user account information without authorization.
5
Who is affected by CVE-2025-40838?
Users and organizations utilizing Ericsson Indoor Connect 8855 are affected by CVE-2025-40838.