{"id":"CVE-2025-11155","title":"The credentials required to access the device's web server are sent in base64 within the HTTP headers","summary":"The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credenti…","severity":"none","cwe":["CWE-261"],"published":"2025-09-29","updated":"2026-10-09","sourceUpdated":"2026-10-09T09:10:00.213","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11155","references":[{"url":"https://www.s21sec.com/cvelist/","label":"50b5080a-775f-442e-83b5-926b5ca517b6"}],"tags":["nvd"],"epss":0.00192,"epssPercentile":0.08092,"ingestedAt":"2026-10-09T09:31:00.983Z","slug":"CVE-2025-11155","body":"## Overview\n\nThe credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}