Back to search
CVE-2025-11155
Published: Sep 29, 2025
Modified: Nov 3, 2025
PUBLISHED
Description
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
| Vendor | Product | Versions |
|---|---|---|
SATO | S86-ex 203dpi | affected 61.00.00.09 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now