CVE-2025-47872

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.
Configurations

No configuration.

History

08 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-08 17:15

Updated : 2025-08-08 20:30


NVD link : CVE-2025-47872

Mitre link : CVE-2025-47872

CVE.ORG link : CVE-2025-47872


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy