A low-privileged remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-018/ |
|
History
Mon, 06 Oct 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks. | A low-privileged remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks. |
Mon, 16 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Jun 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks. | |
| Title | Overly Permissive CORS Policy in WAGO Device Manager | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-06-16T09:45:31.613Z
Updated: 2025-10-07T07:16:37.653Z
Reserved: 2025-02-06T12:30:08.317Z
Link: CVE-2025-25264
Updated: 2025-06-16T18:15:53.456Z
Status : Awaiting Analysis
Published: 2025-06-16T10:15:19.517
Modified: 2025-10-07T08:15:35.103
Link: CVE-2025-25264
No data.