CVE-2025-9495

The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.

Scoring

Severity
HIGH
CVSS base score
8.7
CVSS vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
0.24%
CWE
CWE-602
Published
2025-09-23
Last modified
2026-03-12

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs