CVE-2020-25166: Bbraun Datamodule Compactplus

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

Affected products

  • Bbraun Datamodule Compactplus: version a10 only; version a11 only
  • Bbraun Spacecom: up to and including l81

Published 2022-04-14. Last modified 2026-06-17.