PT-2025-43533 · Tibbo · Tibbo Aggregate Network Manager

Alex Williams

·

Published

2025-10-23

·

Updated

2025-10-23

·

CVE-2025-34156

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tibbo AggreGate Network Manager versions prior to 6.40.05
Description The software reveals sensitive system information through an unauthenticated endpoint. Specifically, the /cwmp/happyaxis.jsp endpoint allows unauthorized access to Java system properties, server path details, and version information. This information disclosure could potentially assist in further compromise of the system.
Recommendations Update Tibbo AggreGate Network Manager to version 6.40.05 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34156

Affected Products

Tibbo Aggregate Network Manager