Reliance on File Name or Extension of Externally-Supplied File
CVE:
CVE-2025-41720
Product: Sauter / modulo 6 devices modu680-AS
Severity: Medium 4.3
Published: 22.10.2025
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.