CVE-2025-25265 - CVE House
Back to Database
Status published Medium CVE-2025-25265

Unauthenticated File Read via Web Interface

Vulnerability Description

A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-25265

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

WAGO CC100 0751-9x01, CC100 0751-9x01, PFC100 G1 0750-810x/xxxx-xxxx, PFC100 G2 0750-811x-xxxx-xxxx, PFC200 G1 750-820x-xxx-xxx, PFC200 G2 750-821x-xxx-xxx, TP600 0762-420x/8000-000x, TP600 0762-430x/8000-000x, TP600 0762-520x/8000-000x, TP600 0762-530x/8000-000x, TP600 0762-620x/8000-000x, TP600 0762-630x/8000-000x, Edge Controller 0752-8303/8000-0002
Vulnerable Versions:
0.0.0

Timeline

Official Publish: June 16th, 2025
Last Modified: November 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)