A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.
References
Configurations
No configuration.
History
18 Nov 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-200 |
18 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-18 19:15
Updated : 2025-11-19 19:14
NVD link : CVE-2025-37160
Mitre link : CVE-2025-37160
CVE.ORG link : CVE-2025-37160
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
