BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.
References
Link | Resource |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-25-185/ | Third Party Advisory |
Configurations
History
21 Aug 2025, 00:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.zerodayinitiative.com/advisories/ZDI-25-185/ - Third Party Advisory | |
CPE | cpe:2.3:o:bectechnologies:router_firmware:-:*:*:*:*:*:*:* | |
First Time |
Bectechnologies router Firmware
Bectechnologies |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
29 Apr 2025, 13:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
23 Apr 2025, 17:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-23 17:16
Updated : 2025-08-21 00:37
NVD link : CVE-2025-2772
Mitre link : CVE-2025-2772
CVE.ORG link : CVE-2025-2772
JSON object : View
Products Affected
bectechnologies
- router_firmware
CWE
CWE-522
Insufficiently Protected Credentials