# CVE-2025-2862

## Summary

- **CVE ID:** CVE-2025-2862
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-261
- **Published:** Mar 28, 2025
- **Last Modified:** Mar 12, 2026

## Description

SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.

## Affected Products

- Arteche — saTECH BCU (2.1.3)

## References

- [CNA](https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._