Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8847 | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered. |
Mon, 31 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered. | |
| Weaknesses | CWE-425 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-03-31T15:58:55.013Z
Reserved: 2025-02-13T01:13:10.937Z
Link: CVE-2025-26689
Updated: 2025-03-31T15:58:49.721Z
Status : Deferred
Published: 2025-03-31T05:15:15.933
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-26689
No data.
OpenCVE Enrichment
No data.
EUVD