The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.
CVSS
No CVSS.
References
Configurations
No configuration.
History
23 Sep 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-23 02:15
Updated : 2025-09-24 18:11
NVD link : CVE-2025-9495
Mitre link : CVE-2025-9495
CVE.ORG link : CVE-2025-9495
JSON object : View
Products Affected
No product.
CWE
CWE-602
Client-Side Enforcement of Server-Side Security