CVE-2025-41689: CWE-306 Missing Authentication for Critical Function in Wiesemann & Theis Motherbox 3
CVE-2025-41689 is a vulnerability in Wiesemann & Theis Motherbox 3 version 1.44 that allows unauthenticated remote attackers to access the device without password protection. This access is limited to read-only retrieval of stored measurement data. The vulnerability is classified as CWE-306, indicating missing authentication for a critical function. It has a high severity with a CVSS score of 7.5.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-41689) affects Wiesemann & Theis Motherbox 3 version 1.44, where an unauthenticated remote attacker can bypass authentication controls and gain read-only access to stored measurement data on the device. The issue is due to missing authentication for a critical function, categorized under CWE-306. There is no indication of impact on data integrity or availability, only confidentiality. No patch or remediation is currently provided by the vendor, and no known exploits are reported in the wild.
Potential Impact
An attacker can remotely access sensitive measurement data stored on the affected device without any authentication. This compromises confidentiality but does not affect data integrity or availability. The unauthorized access is read-only, so the attacker cannot modify or disrupt device functions.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Users should monitor the vendor's advisories for updates. Until a fix is provided, restrict network access to the affected device to trusted users and networks to reduce exposure.
CVE-2025-41689: CWE-306 Missing Authentication for Critical Function in Wiesemann & Theis Motherbox 3
Description
CVE-2025-41689 is a vulnerability in Wiesemann & Theis Motherbox 3 version 1.44 that allows unauthenticated remote attackers to access the device without password protection. This access is limited to read-only retrieval of stored measurement data. The vulnerability is classified as CWE-306, indicating missing authentication for a critical function. It has a high severity with a CVSS score of 7.5.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-41689) affects Wiesemann & Theis Motherbox 3 version 1.44, where an unauthenticated remote attacker can bypass authentication controls and gain read-only access to stored measurement data on the device. The issue is due to missing authentication for a critical function, categorized under CWE-306. There is no indication of impact on data integrity or availability, only confidentiality. No patch or remediation is currently provided by the vendor, and no known exploits are reported in the wild.
Potential Impact
An attacker can remotely access sensitive measurement data stored on the affected device without any authentication. This compromises confidentiality but does not affect data integrity or availability. The unauthorized access is read-only, so the attacker cannot modify or disrupt device functions.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Users should monitor the vendor's advisories for updates. Until a fix is provided, restrict network access to the affected device to trusted users and networks to reduce exposure.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- CERTVDE
- Date Reserved
- 2025-04-16T11:17:48.309Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68a43327ad5a09ad00f42ac1
Added to database: 08/19/2025, 08:17:43 UTC
Last enriched: 07/03/2026, 23:02:04 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 206
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.