CVE-2025-41724: Sauter Ey-Modulo 5 Ecos 5 ECOS504/505

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process will not be restarted by a watchdog and a device reboot is necessary to make it work again.

Affected products

  • Sauter Ey-Modulo 5 Ecos 5 ECOS504/505
  • Sauter Ey-Modulo 5 Modu 5 MODU524
  • Sauter Ey-Modulo 5 Modu 5 MODU525
  • Sauter Modulo 6 Devices MODU612-Lc
  • Sauter Modulo 6 Devices MODU660-As
  • Sauter Modulo 6 Devices MODU680-As

Published 2025-10-22. Last modified 2026-06-17.