The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys from the Software of the affected devices.
https://sauter.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-060.json