PT-2025-44991 · Cfmoto · Cfmoto Ride
Published
2025-11-04
·
Updated
2025-11-10
·
CVE-2025-11690
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CFMOTO RIDE (affected versions not specified)
Description
An Insecure Direct Object Reference (IDOR) vulnerability exists in the
vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. This requires a server-side authorization fix.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cfmoto Ride