CVE-2025-37160
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote at
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.
MEDIUM · CVSS 5.3
EPSS 0.00049
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0