CVE-2025-2980
Last modified
CVE-2025-2980 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. A vulnerability classified as problematic was found in Legrand SMS PowerView 1.x. This vulnerability affects unknown code. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic was found in Legrand SMS PowerView 1.x. This vulnerability affects unknown code. The manipulation of the argument redirect leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2980?
How severe is CVE-2025-2980?
How do I fix CVE-2025-2980?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-29791Access of resource using incompatible type ('type confusion'…7.8
- CVE-2025-29792Use after free in Microsoft Office allows an authorized atta…7.3
- CVE-2025-29793Deserialization of untrusted data in Microsoft Office ShareP…7.2
- CVE-2025-29794Improper authorization in Microsoft Office SharePoint allows…8.8
- CVE-2025-29795Improper link resolution before file access ('link following…7.8
- CVE-2025-29796User interface (ui) misrepresentation of critical informatio…4.7
- CVE-2025-29800Improper privilege management in Microsoft AutoUpdate (MAU) …7.8
- CVE-2025-29801Incorrect default permissions in Microsoft AutoUpdate (MAU) …7.8
- CVE-2025-29802Improper access control in Visual Studio allows an authorize…7.3
- CVE-2025-29803Uncontrolled search path element in Visual Studio Tools for …7.3
- CVE-2025-29804Improper access control in Visual Studio allows an authorize…7.3
- CVE-2025-29805Exposure of sensitive information to an unauthorized actor i…7.5
Are you affected by CVE-2025-2980?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
