CVE-2025-40595

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Configurations

No configuration.

History

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad de Server-side request forgery (SSRF) en la interfaz de SMA1000 Appliance Work Place. Al usar una URL codificada, un atacante remoto no autenticado podría provocar que el dispositivo realice solicitudes a una ubicación no deseada.

14 May 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

14 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-14 17:15

Updated : 2025-05-16 14:43


NVD link : CVE-2025-40595

Mitre link : CVE-2025-40595

CVE.ORG link : CVE-2025-40595


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)