# CVE-2025-2185

## Summary

- **CVE ID:** CVE-2025-2185
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-613
- **Published:** Apr 24, 2025
- **Last Modified:** Mar 12, 2026

## Description

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which
 could permit an attacker to transmit passwords over unencrypted 
connections, resulting in the product becoming vulnerable to 
interception.

## Affected Products

- ALBEDO Telecom — Net.Time - PTP/NTP clock (Serial No. NBC0081P) (1.4.4)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-02)
- [CNA](https://www.albedotelecom.com/contactus.php)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._