Home

Description

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED Reserved 2025-11-20 | Published 2026-05-21 | Updated 2026-05-21 | Assigner TR-CERT




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Problem types

CWE-359 Exposure of private personal information to an unauthorized actor

CWE-522 Insufficiently Protected Credentials

Product status

Default status
unknown

Any version
affected

Credits

Ahmed Resül MERİÇ finder

Mustafa Anıl YILDIRIM coordinator

References

siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0284 government-resource

cve.org (CVE-2025-13477)

nvd.nist.gov (CVE-2025-13477)

Download JSON