# CVE-2025-41742

## Summary

- **CVE ID:** CVE-2025-41742
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-1394
- **Published:** Dec 2, 2025
- **Last Modified:** Mar 12, 2026

## Description

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.

## Affected Products

- Sprecher Automation — SPRECON-E-C (*)
- Sprecher Automation — SPRECON-E-P (*)
- Sprecher Automation — SPRECON-E-T3 (*)

## References

- [CNA](https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/SPR-2511042_de.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.46%
- **EPSS Percentile:** 38.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._