Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered. | |
| Weaknesses | CWE-425 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-03-31T04:49:30.059Z
Updated: 2025-03-31T15:58:55.013Z
Reserved: 2025-02-13T01:13:10.937Z
Link: CVE-2025-26689
Updated: 2025-03-31T15:58:49.721Z
Status : Awaiting Analysis
Published: 2025-03-31T05:15:15.933
Modified: 2025-04-01T20:26:30.593
Link: CVE-2025-26689
No data.