Cleartext Transmission of Sensitive Data via Insecure HTTP Web Interface
Vulnerability Description
Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41708
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Dr. Matthias Kesenheimer by SySS GmbH
- Sebastian Hamann by SySS GmbH
Affected Vendor
Bender
View all reports →