An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.CreditsDeutsche Telekom Security (DT Security)Referenceshttps://certvde.com/en/advisories/VDE-2025-079/https://certvde.com/en/advisories/VDE-2025-096/https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-079.jsonhttps://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-096.json