Home

Description

Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.

PUBLISHED Reserved 2025-11-18 | Published 2025-11-26 | Updated 2025-11-26 | Assigner mitre

References

eslam3kl.gitbook.io

github.com/eslam3kl

eslam3kl.gitbook.io/...sd-gateway-broken-access-control-logs

cve.org (CVE-2025-65239)

nvd.nist.gov (CVE-2025-65239)

Download JSON