CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-41771

mediumCVSS 4.3covered by 1 sourcefirst seen 2026-08-12
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

⚡ Watch CVE-2025-41771

Get an email if CVE-2025-41771 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2025-41771

CVE.org record

Embed the live status

CVE-2025-41771 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-41771 status](https://www.csirts.com/badge/CVE-2025-41771)](https://www.csirts.com/cve/CVE-2025-41771)