CVE-2025-34156

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Oct 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-23 17:15

Updated : 2025-10-23 17:15


NVD link : CVE-2025-34156

Mitre link : CVE-2025-34156

CVE.ORG link : CVE-2025-34156


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere