Description
An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.
Reserved 2025-02-06 | Published 2025-06-16 | Updated 2025-06-16 | Assigner
CERTVDEHIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem types
CWE-942 Permissive Cross-domain Policy with Untrusted Domains
Product status
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70
affected
Default status
unaffected
0.0.0 before 3.10.11 (FW22 Patch 2)
affected
Default status
unaffected
0.0.0 before 03.10.11 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 3.10.11 (FW22 Patch 2)
affected
Default status
unaffected
0.0.0 before 03.10.11 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
Default status
unaffected
0.0.0 before 04.07.01 (FW29)
affected
Default status
unaffected
0.0.0 before 04.07.01 (70)
affected
References
certvde.com/en/advisories/VDE-2025-018/
cve.org (CVE-2025-25264)
nvd.nist.gov (CVE-2025-25264)
Download JSON