vulnti.work

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for s…

Medium CVSS 4.3
CVECVE-2025-41771
First seen2026-08-12 12:30 UTC
Disclosed2026-08-12 08:17 UTC
Last updated2026-08-12 12:30 UTC
Channel statusauto

Summary

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD