CVE-2025-40841: Ericsson Indoor Connect 8855 - Cross-Site Request Forgery Vulnerability
Published Mar 25, 2026
·Updated
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which, if exploited, can lead to unauthorized modification of certain information.
Affected Software
3 affected components
Ericsson Indoor Connect 8855<2025.Q3
All of the following
Ericsson Indoor Connect 8855 Firmware<2025.q3
Ericsson Indoor Connect 8855
Event History
Mar 25, 2026
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40841?
CVE-2025-40841 is classified as a medium severity vulnerability due to its potential for unauthorized information modification.
2
How do I fix CVE-2025-40841?
To fix CVE-2025-40841, upgrade Ericsson Indoor Connect 8855 to version 2025.Q3 or later.
3
What type of vulnerability is CVE-2025-40841?
CVE-2025-40841 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What can happen if CVE-2025-40841 is exploited?
Exploitation of CVE-2025-40841 can lead to unauthorized modification of critical information in the Ericsson Indoor Connect 8855 system.
5
Which versions of Ericsson Indoor Connect 8855 are affected by CVE-2025-40841?
CVE-2025-40841 affects all versions of Ericsson Indoor Connect 8855 prior to 2025.Q3.