Description
Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Application Fingerprinting of sensitive data. This issue affects ZeusWeb: 6.1.31.
Problem types
CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
6.1.31
Timeline
| 2025-11-06: | Vulnerability detection by the researchers |
| 2025-11-11: | Report from researchers to the CNA of HackRTU |
| 2025-11-12: | Report from HackRTU CNA to the provider |
| 2026-02-11: | Vulnerabilities published by HackRTU's CNA |
Credits
Aarón Flecha Menéndez
Víctor Bello Cuevas
References
www.hackrtu.com/blog/CNA-HRTU-0001/
www.hackrtu.com/blog/CNA-CVE-2025-13651/
www.microcom360.com/servicio-zeus-web/
zeus.microcom.es/