CVE-2025-41645: SMA: Sunny Portal demo system privilege escalation
Published May 13, 2025
·Updated
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.
Affected Software
1 affected component
Sunny Portal
Event History
May 13, 2025
CVE Published
via MITRE·08:47 AM
Data Sourced
via MITRE·08:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41645?
CVE-2025-41645 is classified as a high-severity vulnerability due to its potential for remote device hijacking.
2
How do I fix CVE-2025-41645?
To fix CVE-2025-41645, it is advisable to secure demo accounts and restrict unauthorized access to device control.
3
Who is affected by CVE-2025-41645?
Users of the Sunny Portal with unauthenticated demo accounts are affected by CVE-2025-41645.
4
What type of attack is associated with CVE-2025-41645?
CVE-2025-41645 involves an unauthenticated remote attack that can hijack devices linked to a demo account.
5
What mitigation measures can be implemented for CVE-2025-41645?
Mitigation measures for CVE-2025-41645 include disabling demo accounts and monitoring device access logs for unusual activity.