Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14661 | In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing. |
Thu, 24 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Infodraw
Infodraw pmrs-102 Infodraw pmrs-102 Firmware |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:h:infodraw:pmrs-102:-:*:*:*:*:*:*:* cpe:2.3:o:infodraw:pmrs-102_firmware:7.1.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Infodraw
Infodraw pmrs-102 Infodraw pmrs-102 Firmware |
Mon, 21 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Apr 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing. | |
| Weaknesses | CWE-24 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-21T14:33:02.315Z
Reserved: 2025-04-20T00:00:00.000Z
Link: CVE-2025-43928
Updated: 2025-04-21T14:32:50.436Z
Status : Analyzed
Published: 2025-04-20T03:15:35.003
Modified: 2025-04-24T16:00:50.257
Link: CVE-2025-43928
No data.
OpenCVE Enrichment
No data.
EUVD