CVE-2025-41438

The CS5000 Fire Panel is vulnerable due to a default account that exists
 on the panel. Even though it is possible to change this by SSHing into 
the device, it has remained unchanged on every installed system 
observed. This account is not root but holds high-level permissions that
 could severely impact the device's operation if exploited.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---