PT-2025-23480 · Multilaser · Multilaser Sirius Re016 Mlt1.0

Defaultch40S

·

Published

2025-06-02

·

Updated

2025-06-02

·

CVE-2025-5436

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Multilaser Sirius RE016 MLT1.0
Description A problem was found in the processing of the file /cgi-bin/cstecgi.cgi, which leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond.
Recommendations As a temporary workaround, consider disabling access to the /cgi-bin/cstecgi.cgi file until a patch is available. Restrict remote access to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-5436

Affected Products

Multilaser Sirius Re016 Mlt1.0