CVE-2025-41259
NONE—CVSS v3
—CVSS v2
0.01%
EPSS (exploit probability)
CWE-367CWE
Description
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.
Affected routers (0)
No routers currently mapped to this CVE in our database.