CVE Database
/

CVE-2025-48862

Back to search

CVE-2025-48862

Published: Aug 14, 2025

Modified: Aug 14, 2025

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains unencrypted.

VendorProductVersions

Bosch Rexroth AG

ctrlX OS - Setup

affected
1.20.0 - <= 1.20.1
affected
2.6.0 - <= 2.6.1
affected
3.6.0 - <= 3.6.2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now