cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to
access resources.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14678 | CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources. |
Wed, 14 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources. | |
| Weaknesses | CWE-610 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-05-14T13:38:32.786Z
Reserved: 2025-03-27T15:03:20.150Z
Link: CVE-2025-2875
Updated: 2025-05-14T13:38:27.992Z
Status : Deferred
Published: 2025-05-14T09:15:20.097
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-2875
No data.
OpenCVE Enrichment
No data.
EUVD