---
id: CVE-2025-40765
title: >-
  A vulnerability has been identified in TeleControl Server Basic V3.1 (All
  versions >= V3.1.2.2 < V3.1.2.3)
summary: >-
  A vulnerability has been identified in TeleControl Server Basic V3.1 (All
  versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an
  information disclosure vulnerability. This could allow an unauthenticated
  remote attacker to…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: siemens
product: telecontrol_server_basic
affected:
  - telecontrol_server_basic = 3.1.2.2
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40765'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-062309.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00534
epssPercentile: 0.43295
ingestedAt: '2026-10-08T11:31:27.374Z'
---

## Overview

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.

## Affected

- `telecontrol_server_basic = 3.1.2.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
