Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18381 | A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows an unauthenticated remote attacker to read files from the system’s file structure. |
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-018/ |
|
Fri, 21 Nov 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows an unauthenticated remote attacker to read files from the system’s file structure. | A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 16 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Jun 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows an unauthenticated remote attacker to read files from the system’s file structure. | |
| Title | Unauthenticated File Read via Web Interface | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-11-21T11:38:18.852Z
Reserved: 2025-02-06T12:30:08.318Z
Link: CVE-2025-25265
Updated: 2025-06-16T18:13:12.009Z
Status : Deferred
Published: 2025-06-16T10:15:20.807
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-25265
No data.
OpenCVE Enrichment
No data.
EUVD