CVE-2025-41708

7.4

Bender · CC612, CC613, ICC15xx, ICC16xx, ICC13xx

Bender devices use unsecure default HTTP configurations for the web interface, allowing unauthenticated network-adjacent attackers to intercept sensitive data transmitted in cleartext.

Executive summary

A critical cleartext transmission vulnerability in Bender interface products exposes sensitive data to interception by unauthenticated attackers on the same network.

Vulnerability

The vulnerability involves the use of cleartext HTTP for web interface communication, classified under CWE-319, which permits unauthenticated attackers to sniff network traffic.

Business impact

The reliance on unencrypted HTTP communication presents a significant risk to organizational confidentiality and integrity. If sensitive credentials or configuration data are intercepted, an attacker could potentially gain unauthorized access to the device management interface, leading to further compromise of the operational environment. Given the CVSS score of 7.4, this vulnerability represents a high risk that requires immediate attention to prevent unauthorized data exposure.

Remediation

Immediate Action: Consult the official vendor advisory provided by Bender at https://certvde.com/de/advisories/VDE-2025-084 to identify available firmware updates or configuration hardening steps.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts or unusual patterns originating from the management interface.

Compensating Controls: Implement network segmentation to restrict access to the web interface to authorized personnel only, and utilize VPNs or encrypted tunnels to encapsulate traffic until a secure configuration can be enforced.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing affected Bender devices must prioritize the implementation of secure communication protocols. Because the vulnerability stems from a fundamental default configuration flaw, administrators should verify if the vendor provides a patch to enforce HTTPS or if manual configuration changes are required to disable cleartext access. Failure to secure these interfaces increases the risk of credential theft and unauthorized system modification.

Sources

Originally found and disclosed by Dr. Matthias Kesenheimer by SySS GmbH, Sebastian Hamann by SySS GmbH, per the CVE Program record.