{"id":"CVE-2025-9497","title":"Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.","summary":"Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-798"],"vendor":"microchip","product":"timeprovider_4100_firmware","affected":["timeprovider_4100_firmware < 2.5.0"],"patched":["timeprovider_4100_firmware 2.5.0"],"published":"2026-03-28","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-9497","references":[{"url":"https://www.gruppotim.it/en/footer/TIM-red-team.html","label":"dc3f6da9-85b5-4a73-84a2-2ec90b40fca5"},{"url":"https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-hardcoded-upgrade-decryption-passwords","label":"dc3f6da9-85b5-4a73-84a2-2ec90b40fca5"}],"tags":["nvd"],"epss":0.00317,"epssPercentile":0.24864,"ingestedAt":"2026-08-12T19:54:27.175Z","slug":"CVE-2025-9497","body":"## Overview\n\nUse of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.\n\n## Affected\n\n- `timeprovider_4100_firmware < 2.5.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `timeprovider_4100_firmware 2.5.0`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}