Junglewise Threat Intelligence

CVE-2025-12995: Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used t

CVE-2025-12995 · Severity: high · CVSS 8.1 · Published 2025-12-04

Technologies: Medtronic Carelink Network. Vendors: Medtronic.

Executive brief

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

Affected products

  • medtronic carelink_network

Related threats