vde-2025-084

HIGH CVSS 7.4 csaf_bendergmbhcokg
Description

Bender is publishing this advisory to inform customers about a security vulnerability in the Charge Controller product families. Bender has analyzed the weakness and determined that the electrical safety of the devices is not affected. Bender considers the weakness to be of high risk and it should be patched immediately.

Timeline
Published
2025-09-08 07:00 UTC
Last Modified
2025-09-08
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      },
      {
        "names": [
          "Dr. Matthias Kesenheimer",
          "Sebastian Hamann"
        ],
        "organization": " SySS GmbH",
        "summary": "reporting",
        "urls": [
          "https://www.syss.de"
        ]
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "Bender is publishing this advisory to inform customers about a security vulnerability in the Charge Controller product families. Bender has analyzed the weakness and determined that the electrical safety of the devices is not affected. Bender considers the weakness to be of high risk and it should be patched immediately.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "To use HTTPS on the web interface, enable it in the settings.",
        "title": "Mitigation"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@bender.de",
      "name": "Bender GmbH & Co. KG",
      "namespace": "https://www.bender.de"
    },
    "references": [
      {
        "category": "self",
        "summary": "VDE-2025-084: Bender Charge Controller Vulnerability - Unsecure Communication - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2025-084/"
      },
      {
        "category": "self",
        "summary": "VDE-2025-084: Bender Charge Controller Vulnerability - Unsecure Communication - CSAF",
        "url": "https://bender.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-084.json"
      },
      {
        "category": "external",
        "summary": "Vendor PSIRT",
        "url": "https://www.bender.de"
      },
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for Bender GmbH & Co. KG",
        "url": "https://certvde.com/en/advisories/vendor/bender/"
      }
    ],
    "title": "Bender Charge Controller Vulnerability - Unsecure Communication",
    "tracking": {
      "aliases": [
        "VDE-2025-084"
      ],
      "current_release_date": "2025-09-08T07:00:00.000Z",
      "generator": {
        "date": "2025-08-31T06:46:46.505Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.33"
        }
      },
      "id": "VDE-2025-084",
      "initial_release_date": "2025-09-08T07:00:00.000Z",
      "revision_history": [
        {
          "date": "2025-09-08T07:00:00.000Z",
          "number": "1",
          "summary": "initial version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "CC612",
                "product": {
                  "name": "CC612",
                  "product_id": "CSAFPID-11001"
                }
              },
              {
                "category": "product_name",
                "name": "CC613",
                "product": {
                  "name": "CC613",
                  "product_id": "CSAFPID-11002"
                }
              },
              {
                "category": "product_name",
                "name": "ICC15xx",
                "product": {
                  "name": "ICC15xx",
                  "product_id": "CSAFPID-11003"
                }
              },
              {
                "category": "product_name",
                "name": "ICC16xx",
                "product": {
                  "name": "ICC16xx",
                  "product_id": "CSAFPID-11004"
                }
              },
              {
                "category": "product_name",
                "name": "ICC13xx",
                "product": {
                  "name": "ICC13xx",
                  "product_id": "CSAFPID-11005"
                }
              }
            ],
            "category": "product_family",
            "name": "Hardware"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "vers:all/*",
                "product": {
                  "name": "Firmware vers:all/*",
                  "product_id": "CSAFPID-21001"
                }
              }
            ],
            "category": "product_family",
            "name": "Firmware"
          }
        ],
        "category": "vendor",
        "name": "Bender"
      }
    ],
    "product_groups": [
      {
        "group_id": "CSAFGID-0001",
        "product_ids": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ],
        "summary": "Affected products"
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on CC612",
          "product_id": "CSAFPID-31001"
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on CC613",
          "product_id": "CSAFPID-31002"
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on ICC15xx",
          "product_id": "CSAFPID-31003"
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11003"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on ICC16xx",
          "product_id": "CSAFPID-31004"
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11004"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware vers:all/* installed on ICC13xx",
          "product_id": "CSAFPID-31005"
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11005"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-41708",
      "cwe": {
        "id": "CWE-319",
        "name": "Cleartext Transmission of Sensitive Information"
      },
      "notes": [
        {
          "category": "description",
          "text": "Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "Enable use of HTTPS in the charge controller configuration Web UI settings>system>https",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.4,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.4,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ],
      "title": "CVE-2025-41708"
    }
  ]
}
View JSON API Download JSON