BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.
References
Link | Resource |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-25-185/ |
Configurations
No configuration.
History
23 Apr 2025, 17:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-23 17:16
Updated : 2025-04-23 17:16
NVD link : CVE-2025-2772
Mitre link : CVE-2025-2772
CVE.ORG link : CVE-2025-2772
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials