CVE-2025-41719: Sauter Ey-Modulo 5 Ecos 5 ECOS504/505
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password.
Affected products
- Sauter Ey-Modulo 5 Ecos 5 ECOS504/505
- Sauter Ey-Modulo 5 Modu 5 MODU524
- Sauter Ey-Modulo 5 Modu 5 MODU525
- Sauter Modulo 6 Devices MODU612-Lc
- Sauter Modulo 6 Devices MODU660-As
- Sauter Modulo 6 Devices MODU680-As
Published 2025-10-22. Last modified 2026-06-17.