WEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATION
Vulnerability Description
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11155
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Víctor Bello Cuevas
- Aarón Flecha Menéndez
- Iván Alonso Álvarez
References
Affected Vendor
SATO
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.