IoT & Hardware
Information Disclosure
Unprotected Transport of Credentials on Murrelektronik Impact67 Pro
Murrelektronik: Unprotected Transport of Credentials The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8 transmits login credentials over unencrypted HTTP using a GET request.
.png)
Overview
Murrelektronik: Unprotected Transport of Credentials
The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8
transmits login credentials over unencrypted HTTP using a GET request. The device does
not offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network.
Vulnerability details
Murrelektronik: Unprotected Transport of Credentials The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8 transmits login credentials over unencrypted HTTP using a GET request.
Disclosure timeline
2025-09-26 reported to the vendor
2025-09-29 reported to the CERTVDE
2025-10-14 Advisory Released by Murrelektronik GmbH on CERTVDE Portal
References
Credits
Abhishek Pandey
















