---
id: CVE-2025-48981
title: >-
  An insecure implementation of the proprietary protocol DNET in Product CGM
  MEDICO allows attackers within the intranet to eavesdrop and manipulate data
  on the protocol because encryption is optional for this connection.
summary: >-
  An insecure implementation of the proprietary protocol DNET in Product CGM
  MEDICO allows attackers within the intranet to eavesdrop and manipulate data
  on the protocol because encryption is optional for this connection.
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'
cwe:
  - CWE-311
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48981'
references:
  - url: >-
      https://www.cgm.com/deu_de/allgemein/cybersecurity-en/security-advisoriy.html
    label: support@hackerone.com
tags:
  - nvd
epss: 0.00118
epssPercentile: 0.01566
ingestedAt: '2026-10-08T13:42:54.989Z'
---

## Overview

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
