CVE-2026-41918
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.19%
- CWE
- CWE-525
- Published
- 2026-06-02
- Last modified
- 2026-06-02
Affected products
- Siemens RUGGEDCOM RST2428P
Weakness type
Related vulnerabilities
- CVE-2026-13697 — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
- CVE-2024-23571 — HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate...
- CVE-2026-41322 — @astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed
- CVE-2025-15554 — Admin Passwords Cached by Browsers in Truesec LAPSWebUI
- CVE-2025-36364 — IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters.
- CVE-2026-27514 — Tenda F3 Plaintext Credential Exposure in Configuration Download
- CVE-2026-24437 — Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
- CVE-2025-52659 — HCL AION is affected by a Cacheable HTTP Response vulnerability