CVE-2025-52549
CRITICALDescription
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| copeland | e3_supervisory_controller_firmware |
| copeland | site_supervisor_bx_860-1240 |
| copeland | site_supervisor_bxe_860-1245 |
| copeland | site_supervisor_cx_860-1260 |
| copeland | site_supervisor_cxe_860-1265 |
| copeland | site_supervisor_rx_860-1220 |
| copeland | site_supervisor_rxe_860-1225 |
| copeland | site_supervisor_sf_860-1200 |
References
Other References
Frequently Asked Questions
What is CVE-2025-52549? +
How severe is CVE-2025-52549? +
What products are affected by CVE-2025-52549? +
How do I check if I'm vulnerable to CVE-2025-52549? +
Related Vulnerabilities
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials …
Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes …
Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability …
Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges …
The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an …
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using …