CVE-2025-41771
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Aug 12, 2026
Vendor
unknown
Description
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.