CVE-2025-41712: Janitza Umg 96rm-E 230v5222062

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.

Affected products

  • Janitza Umg 96rm-E 230v5222062: from 0.0, up to and including 3.13
  • Janitza Umg 96rm-E 24v5222063: from 0.0, up to and including 3.13
  • Weidmueller Energy Meter 750-230 2540910000: from 0.0, up to and including 3.13
  • Weidmueller Energy Meter 750-24 2540900000: from 0.0, up to and including 3.13

Published 2026-03-10. Last modified 2026-06-17.