CVE-2025-41731: Jumo: Insufficient entropy in PRNG may lead to root access
A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might be able to brute force the password in a timely manner and thus gain root access to the device if the debug interface is still enabled.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41731?
CVE-2025-41731 has a severity rating of 7.4, categorized as high.
What type of access can an attacker gain through CVE-2025-41731?
An attacker can gain root access to the device by exploiting CVE-2025-41731.
How does CVE-2025-41731 allow for exploitation?
CVE-2025-41731 allows for exploitation through insufficient entropy in the PRNG used for password generation.
Who is affected by CVE-2025-41731?
CVE-2025-41731 affects devices using Jumo's debug-interface where the password generation algorithm is employed.
What mitigation strategies are recommended for CVE-2025-41731?
It is recommended to enhance the randomness of the password generation algorithm to mitigate CVE-2025-41731.