Multiple vulnerabilities in Janitza UMG 96RM-E
好的,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,找出关键信息。 文章主要讲的是Janitza UMG 96RM-E设备发现了四个漏洞,影响版本是低于3.14的固件。漏洞类型包括命令注入、硬编码凭据、加密算法问题和权限分配错误。风险等级是关键,已经修复了,建议升级到3.14版本,并且在网络防护方面给出了一些建议。 接下来,我需要将这些信息浓缩到100字以内。要确保涵盖设备型号、漏洞数量、风险等级、修复情况以及防护建议。同时,语言要简洁明了,避免使用复杂的术语。 可能的结构是:设备型号+发现漏洞数量+漏洞类型+风险等级+修复建议+防护措施。这样既全面又简洁。 最后,检查字数是否在限制内,并确保没有遗漏重要信息。 </think> Janitza UMG 96RM-E设备被发现存在四个安全漏洞(CVE-2025-41709至CVE-2025-41712),包括命令注入、硬编码凭据、加密算法问题及权限分配错误。这些漏洞允许远程攻击者完全控制设备或获取敏感信息。建议更新至固件3.14版本,并采取网络防护措施以减少风险。 2025-11-4 00:0:0 Author: github.security.telekom.com(查看原文) 阅读量:7 收藏

Several vulnerabilities were discovered during testing of a Janitza UMG 96RM-E device.

Details

  • Product: UMG 96RM-E (both 24V and 230V versions)
  • Affected Version: firmware versions below 3.14
  • Vulnerability Type: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) (CWE-78), Use of Hard-coded Credentials (CWE-798), Use of a Broken or Risky Cryptographic Algorithm (CWE-327) and Incorrect Permission Assignment for Critical Resource (CWE-732)
  • Risk Level: Critical
  • Vendor URL: https://www.janitza.com/
  • Vendor acknowledged vulnerability: Yes
  • Vendor Status: Updated firmware available
  • CVEs: CVE-2025-41709, CVE-2025-41710, CVE-2025-41711, CVE-2025-41712

The vulnerabilities were discovered during testing a device of type UMG 96RM-E. These vulnerabilities in combination allow an unauthenticated remote attacker to fully compromise the system including remote code execution.

It is strongly advised to update to the newest version. The vulnerabilities are fixed in version 3.14. In addition, such devices shall be operated in a closed network protected by a suitable firewall. Network access to the device should be limited to only enable necessary components to access it and protocols not necessary for the operation should be blocked.

CVE-2025-41709: Command injection via Modbus

A high privileged remote attacker can perform a command injection via Modbus to gain read and write access on the affected device. This vulnerability has a CVSSv3.1 Base Score of 9.8 and is rated CRITICAL.

CVE-2025-41710: Use of Hard-coded Credentials

An unauthenticated remote attacker may use hardcoded credentials to get access to the previously activated FTP Server with limited write privileges. This vulnerability has a CVSSv3.1 Base Score of 5.3 and is rated MEDIUM.

CVE-2025-41711: Use of firmware images to extract password hashes and brute force plaintext passwords

An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access. This vulnerability has a CVSSv3.1 Base Score of 5.3 and is rated MEDIUM.

CVE-2025-41712: Incorrect Permission Assignment on the device

An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server. This vulnerability has a CVSSv3.1 Base Score of 6.5 and is rated MEDIUM.

References

Credits


文章来源: https://github.security.telekom.com/2025/11/multiple-vulnerabilities-in-janitza-umg96rm-e.html
如有侵权请联系:admin#unsafe.sh