Junglewise Threat Intelligence

CVE-2025-41743: Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to e

CVE-2025-41743 · Severity: medium · CVSS 4 · Published 2025-12-02

Technologies: Sprecher-Automation Sprecon-E-C, Sprecher-Automation Sprecon-E-P, Sprecher-Automation Sprecon-E-T3, Sprecher-Automation Sprecon-E-P Firmware, Sprecher-Automation Sprecon-E-C Firmware, Sprecher-Automation Sprecon-E-T3 Firmware. Vendors: Sprecher-Automation.

Executive brief

Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes.

Affected products

  • sprecher-automation sprecon-e-c
  • sprecher-automation sprecon-e-p
  • sprecher-automation sprecon-e-t3
  • sprecher-automation sprecon-e-p_firmware
  • sprecher-automation sprecon-e-c_firmware
  • sprecher-automation sprecon-e-t3_firmware

Related threats