CVE-2025-3200: Wiesemann & Theis Com-Server++
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and connected systems.
Affected products
- Wiesemann & Theis Com-Server++: from 0.0.0, before 1.60 (fixed in 1.60)
- Wiesemann & Theis Com-Server 20ma: from 0.0.0, before 1.60 (fixed in 1.60)
- Wiesemann & Theis Com-Server Oem: from 0.0.0, before 1.60 (fixed in 1.60)
- Wiesemann & Theis Com-Server Poe 3x Isolated: from 0.0.0, before 1.60 (fixed in 1.60)
- Wiesemann & Theis Com-Server Ul: from 0.0.0, before 1.60 (fixed in 1.60)
Published 2025-04-28. Last modified 2026-06-17.