Description
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.
Published: 2025-04-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12171 BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.
History

Thu, 21 Aug 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Bectechnologies
Bectechnologies router Firmware
CPEs cpe:2.3:o:bectechnologies:router_firmware:-:*:*:*:*:*:*:*
Vendors & Products Bectechnologies
Bectechnologies router Firmware
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 23 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
Description BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.
Title BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability
Weaknesses CWE-522
References
Metrics cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Bectechnologies Router Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2025-04-23T17:49:13.439Z

Reserved: 2025-03-24T19:44:31.977Z

Link: CVE-2025-2772

cve-icon Vulnrichment

Updated: 2025-04-23T17:49:08.498Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-23T17:16:55.290

Modified: 2025-08-21T00:37:29.590

Link: CVE-2025-2772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses