Junglewise Threat Intelligence
CVE-2025-41743: Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to e
CVE-2025-41743 · Severity: medium · CVSS 4 · Published 2025-12-02
Technologies: Sprecher-Automation Sprecon-E-C, Sprecher-Automation Sprecon-E-P, Sprecher-Automation Sprecon-E-T3, Sprecher-Automation Sprecon-E-P Firmware, Sprecher-Automation Sprecon-E-C Firmware, Sprecher-Automation Sprecon-E-T3 Firmware. Vendors: Sprecher-Automation.
Executive brief
Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes.
Affected products
- sprecher-automation sprecon-e-c
- sprecher-automation sprecon-e-p
- sprecher-automation sprecon-e-t3
- sprecher-automation sprecon-e-p_firmware
- sprecher-automation sprecon-e-c_firmware
- sprecher-automation sprecon-e-t3_firmware