IoT & Hardware

Information Disclosure

Unprotected Transport of Credentials on Murrelektronik Impact67 Pro

Murrelektronik: Unprotected Transport of Credentials The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8 transmits login credentials over unencrypted HTTP using a GET request.

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS89
PUBLISHED
2025-11-09
CVE IDs
CVE-2025-41718
VENDORS
Murrelektronik GmbH
PUBLIC EXPLOIT
None indexed
CWE
CWE-319
PRODUCT
Impact67 Pro (54620/54630/54631/54632)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Murrelektronik: Unprotected Transport of Credentials

The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8

transmits login credentials over unencrypted HTTP using a GET request. The device does

not offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network.

Vulnerability details

Vulnerability details

CVE-2025-41718
CWE-319
High | 7.5

Murrelektronik: Unprotected Transport of Credentials The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8 transmits login credentials over unencrypted HTTP using a GET request.

Auth:
None (remote)
Impact:
Sensitive data disclosure
DISCLOSURE

Disclosure timeline

2025-09-26 reported to the vendor

2025-09-29 reported to the CERTVDE

2025-10-14 Advisory Released by Murrelektronik GmbH on CERTVDE Portal

Credits

Abhishek Pandey