What is CVE-2025-41771?
CVE-2025-41771 allows an authenticated attacker with low privileges to perform SQL injection via an endpoint in the controller’s web interface. The vulnerability only affects a SQLite database used for storing notification messages, limiting the impact to the notification functionality. Restrict access to the affected function or apply vendor patches when available.
Azərbaycanca: CVE-2025-41771 zəifliyi autentifikasiya olunmuş aşağı səlahiyyətli istifadəçiyə kontrollerin veb interfeysində SQL injection tətbiq etməyə imkan verir. Bu, yalnız bildiriş mesajlarını saxlayan SQLite verilənlər bazasına təsir edir, lakin təsir dairəsi məhduddur. Bu funksiyadan istifadəni məhdudlaşdırmaq və ya istehsalçı tərəfindən yamaq tətbiq olunana qədər giriş nəzarətini gücləndirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What type of vulnerability is CVE-2025-41771 and who can exploit it?
CVE-2025-41771 is an SQL injection vulnerability that can be exploited by an authenticated attacker with low privileges via the controller’s web interface.
What is the impact scope of CVE-2025-41771?
The vulnerability only affects a SQLite database used for storing notification messages, so the impact is limited to the notification functionality.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.