{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-18T13:49:10.200","vulnerabilities":[{"cve":{"id":"CVE-2025-48417","sourceIdentifier":"551230f0-3615-47bd-b7cc-93e92e730bbf","published":"2025-05-21T13:16:03.080","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware and are shipped with the update files. An attacker can use the private key to perform man-in-the-middle attacks against users of the admin interface. The files are located in /etc/ssl (e.g. salia.local.crt, salia.local.key and salia.local.pem). There is no option to upload/configure custom TLS certificates."},{"lang":"es","value":"El certificado y la clave privada utilizados para proporcionar seguridad de la capa de transporte a las conexiones a la interfaz web (puerto TCP 443) están codificados en el firmware y se incluyen con los archivos de actualización. Un atacante puede usar la clave privada para realizar ataques de intermediario contra los usuarios de la interfaz de administración. Los archivos se encuentran en /etc/ssl (p. ej., salia.local.crt, salia.local.key y salia.local.pem). No existe la opción de cargar ni configurar certificados TLS personalizados."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"551230f0-3615-47bd-b7cc-93e92e730bbf","type":"Secondary","description":[{"lang":"en","value":"CWE-321"}]}],"references":[{"url":"https://r.sec-consult.com/echarge","source":"551230f0-3615-47bd-b7cc-93e92e730bbf"},{"url":"http://seclists.org/fulldisclosure/2025/May/23","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}