CVE-2025-40946Patch

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All versions), blueplanet 125 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 137 TL3 (All versions), blueplanet 150 TL3 (All versions), blueplanet 150 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 155 TL3 (All versions), blueplanet 155 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 165 TL3 (All versions), blueplanet 165 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 25.0 NX3-33.0 NX3 (All versions), blueplanet 3.0 NX3-20.0 NX3 (All versions), blueplanet 3.0 TL3-60.0 TL3 (All versions), blueplanet 3.0-5.0 NX1 (All versions), blueplanet 360 NX3 M6 (All versions), blueplanet 50.0 NX3-60.0 NX3 (All versions), blueplanet 87.0 TL3 (All versions), blueplanet 87.0 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 92.0 TL3 (All versions), blueplanet 92.0 TL3 GEN2 (All versions < V6.1.4.9), blueplanet gridsave 110 TL3-S (All versions < V3.91), blueplanet gridsave 137 TL3-S (All versions < V3.91), blueplanet gridsave 92.0 TL3-S (All versions < V3.91), blueplanet hybrid 10.0 TL3 (All versions), blueplanet hybrid 6.0 NH3-12.0 NH3 (All versions). A CRC16-based algorithm for generating Technical Service credentials could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthorized access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-06-20: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 1Technical Details · 2026-06-20: 105-1206-20
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-06-201
Disclosure1
Full discourse2 posts
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2025-40946: Serial-Number-Derived Credentials Expose Siemens KACO Blueplanet Inverters https://breachspider.com/intel/2026-06-20-cve-2025-40946-serial-number-derived-credentials-expose-siem #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The tweet announces a new vulnerability (CVE-2025-40946) affecting Siemens KACO Blueplanet Inverters, describing that credentials can be derived from serial numbers, with no mention of exploitation or mitigation.

    0000050
    2.3K followersView on X
  • Entity@0x2ed3bb60
    Patch

    🚨 HIGH: CVE-2025-40946 in Siemens blueplanet inverters. CRC16 weakness allows credential derivation from serial number. Patch to V6.1.4.9+ (GEN2) or V3.91+ (gridsafe). Exposure: remote admin access. https://0x2ed3bb60.xyz/threat/e92c5f6337b58067

    Post summary

    The post announces CVE-2025-40946, details a CRC16 weakness that permits credential derivation, and provides patch guidance for affected Siemens BluePlanet inverters.

    0000011
    7 followersView on X

Explore more