CVE Vulnerabilities

CVE-2025-2862

Weak Encoding for Password

Published: Mar 28, 2025 | Modified: Oct 15, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the devices system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.

Weakness

Obscuring a password with a trivial encoding does not protect the password.

Affected Software

NameVendorStart VersionEnd Version
Satech_bcu_firmwareArteche2.1.3 (including)2.1.3 (including)

Potential Mitigations

References