CVE-2025-57434

Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what follows.
Configurations

No configuration.

History

22 Sep 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-287
CWE-798

22 Sep 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 17:16

Updated : 2025-09-22 21:22


NVD link : CVE-2025-57434

Mitre link : CVE-2025-57434

CVE.ORG link : CVE-2025-57434


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-798

Use of Hard-coded Credentials