Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-53v5-9752-qq92 | NutzBoot Incorrect Privilege Assignment vulnerability |
Tue, 24 Feb 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nutzam:nutzboot:*:*:*:*:*:*:*:* |
Tue, 30 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:nutzam:nutzboot:*:*:*:*:*:maven:*:* |
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nutzam
Nutzam nutzboot |
|
| Vendors & Products |
Nutzam
Nutzam nutzboot |
Mon, 01 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Transaction API. The manipulation of the argument from/to/wei leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | |
| Title | nutzam NutzBoot Transaction API EthModule.java improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-24T06:39:23.584Z
Reserved: 2025-11-30T14:12:59.907Z
Link: CVE-2025-13806
Updated: 2025-12-01T14:48:47.524Z
Status : Analyzed
Published: 2025-12-01T05:16:00.013
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-13806
No data.
OpenCVE Enrichment
Updated: 2025-12-01T15:17:59Z
Github GHSA