B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus
No sign of exploitation. No public exploitation artifact known so far.
The B. Braun SpaceCom and Data module compactplus devices have a flaw in their admin interface that allows attackers to trick users into visiting malicious websites by disguising harmful links as legitimate ones. This can lead to credential theft or malware infection.
An open redirect vulnerability exists in the administrative interface of affected B. Braun devices (SpaceCom L81/U61 and earlier, Data module compactplus A10/A11) that allows an unauthenticated attacker to craft a malicious URL redirecting authenticated users to external sites. The attack vector is network-based and relies on social engineering; successful exploitation can compromise user credentials or deliver malware.