PT-2025-31155 · Xorux · Xormon-Ng+1

Jim Becher

·

Published

2025-07-28

·

Updated

2025-10-09

·

CVE-2025-54766

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined. (affected versions not specified)
Description An API endpoint intended for web application administrators is accessible to lower-level read-only users. This allows unauthorized export of the appliance configuration, potentially exposing sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2025-54766

Affected Products

Xormon-Ng
Xormon