CVE-2025-41685: SMA Ennexos.sunnyportal.com

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.

Affected products

  • SMA Ennexos.sunnyportal.com: before 15.08.2025 (fixed in 15.08.2025)

Published 2025-08-19. Last modified 2026-06-17.