Threats Tagged 'cve-2025-40755'
View all threats tagged with 'cve-2025-40755'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-40755'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-40755 is a high-severity SQL injection vulnerability in Siemens SINEC NMS versions prior to 4.0 SP1. It affects the getTotalAndFilterCounts endpoint and requires low-privileged authenticated access. Exploitation allows attackers to insert arbitrary SQL commands, potentially leading to privilege escalation and full compromise of the system's confidentiality, integrity, and availability. No user interaction is needed beyond authentication. Although no known exploits are currently in the wild, the vulnerability's ease of exploitation and impact make it a critical concern for organizations using SINEC NMS. European organizations relying on Siemens industrial network management solutions are particularly at risk. Mitigation requires applying vendor patches once available, restricting access to the management interface, and implementing strict input validation and monitoring. Countries with significant industrial infrastructure and Siemens deployments, such as Germany, France, Italy, and the UK, are most likely to be affected. Join the discussion | CVE Database V5 | 10/14/2025, 09:15:13 UTC Added: 10/14/2025, 09:21:53 UTC |
Showing 1 to 1 of 1 result