CVE-2025-48862
Last modified
CVE-2025-48862 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains unencrypted.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains unencrypted.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-48862?
How severe is CVE-2025-48862?
How do I fix CVE-2025-48862?
Are you affected by CVE-2025-48862?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
