Home

Description

Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.

PUBLISHED Reserved 2025-04-16 | Published 2026-01-26 | Updated 2026-01-26 | Assigner INCIBE




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Product status

Default status
unaffected

8.5.3290.0
affected

Credits

Julen Garrido Estevez finder

References

www.incibe.es/...lnerabilities-altitude-communication-server

cve.org (CVE-2025-41083)

nvd.nist.gov (CVE-2025-41083)

Download JSON