CVE-2025-59461: API does not require authentication
Published Oct 27, 2025
·Updated
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
Affected Software
2 affected components
All of the following
SICK Tloc100-100 Firmware
SICK Tloc100-100
Event History
Oct 27, 2025
CVE Published
via MITRE·10:11 AM
Data Sourced
via MITRE·10:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59461?
CVE-2025-59461 has been classified with a high severity due to the potential for remote unauthorized access to sensitive data.
2
How does CVE-2025-59461 affect the SICK Tloc100-100 Firmware?
CVE-2025-59461 allows an unauthenticated attacker to access or modify sensitive data in the SICK Tloc100-100 Firmware.
3
Who is affected by CVE-2025-59461?
Any user of SICK Tloc100-100 with the vulnerable firmware version is affected by CVE-2025-59461.
4
How do I fix CVE-2025-59461?
To mitigate CVE-2025-59461, update your SICK Tloc100-100 Firmware to the latest patched version provided by SICK.
5
Can CVE-2025-59461 disrupt services?
Yes, CVE-2025-59461 may allow an attacker to disrupt services by accessing or modifying operational data.