CVE Watchtower β Back to CVE ListCVE-2025-41720NVDDescriptionA low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.Severity LevelMEDIUM (4.3)Published Date22/10/2025Last Modified22/10/2025Exploitation Status????Referenceshttps://sauter.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-060.json