CVE-2025-41657: Auma AC1.2
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.
Affected products
- Auma AC1.2: from 01.01.2024, before 09.05.2025 (fixed in 09.05.2025)
- Auma Profox: from 01.01.2024, before 09.05.2025 (fixed in 09.05.2025)
Published 2025-06-10. Last modified 2026-06-17.