Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27715 | Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5. |
| Link | Providers |
|---|---|
| https://mobatimemtsl.github.io/Vulnerability-References/ |
|
Tue, 27 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5. | |
| Title | Missing Authentication & Authorization in Web-API allows adversary unrestricted access | |
| Weaknesses | CWE-306 CWE-862 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2025-05-27T13:59:38.622Z
Reserved: 2025-03-17T12:57:47.910Z
Link: CVE-2025-2407
Updated: 2025-05-27T13:59:35.723Z
Status : Deferred
Published: 2025-05-27T08:15:19.610
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-2407
No data.
OpenCVE Enrichment
No data.
EUVD