CVE-2025-41452: Post auth nginx configuration injection in Danfoss AK-SM8xxA Series
Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41452?
CVE-2025-41452 is classified as a critical vulnerability due to its potential to cause a denial of service attack.
How do I fix CVE-2025-41452?
To mitigate CVE-2025-41452, upgrade the Danfoss AK-SM8xxA Series software to version 4.3.1 or later.
What products are affected by CVE-2025-41452?
CVE-2025-41452 affects the Danfoss AK-SM8xxA Series prior to version 4.3.1.
What type of attack can CVE-2025-41452 lead to?
CVE-2025-41452 could lead to a denial of service attack due to improper handling of exceptional conditions.
Is CVE-2025-41452 a remote or local vulnerability?
CVE-2025-41452 is a post-authenticated vulnerability, indicating it requires access to the system's web interface.