CVE-2025-2125

A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of the component PDF Document Handler. The manipulation of the argument nsr leads to improper control of resource identifiers. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/yago3008/cves Third Party Advisory
https://vuldb.com/?ctiid.299038 Permissions Required VDB Entry
https://vuldb.com/?id.299038 VDB Entry
https://vuldb.com/?submit.509856 VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:assaabloy:control_id_rhid:25.2.25.0:*:*:*:*:*:*:*

History

24 Mar 2025, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:assaabloy:control_id_rhid:25.2.25.0:*:*:*:*:*:*:*
References () https://github.com/yago3008/cves - () https://github.com/yago3008/cves - Third Party Advisory
References () https://vuldb.com/?ctiid.299038 - () https://vuldb.com/?ctiid.299038 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.299038 - () https://vuldb.com/?id.299038 - VDB Entry
References () https://vuldb.com/?submit.509856 - () https://vuldb.com/?submit.509856 - VDB Entry
Summary
  • (es) Se ha detectado una vulnerabilidad en Control iD RH iD 25.2.25.0 y se ha clasificado como problemática. Esta vulnerabilidad afecta al código desconocido del archivo /v2/report.svc/comprovante_marcacao/?companyId=1 del componente PDF Document Handler. La manipulación del argumento nsr conduce a un control inadecuado de los identificadores de recursos. El ataque puede iniciarse de forma remota. Se contactó al proveedor con anticipación sobre esta revelación, pero no respondió de ninguna manera.
CWE CWE-639
First Time Assaabloy
Assaabloy control Id Rhid

09 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-09 16:15

Updated : 2025-03-24 13:55


NVD link : CVE-2025-2125

Mitre link : CVE-2025-2125

CVE.ORG link : CVE-2025-2125


JSON object : View

Products Affected

assaabloy

  • control_id_rhid
CWE
CWE-99

Improper Control of Resource Identifiers ('Resource Injection')

CWE-639

Authorization Bypass Through User-Controlled Key