PT-2025-45451 · Pig · Pig

Published

2025-11-07

·

Updated

2025-11-12

·

CVE-2025-63691

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pig-mesh In Pig versions 3.8.2 and below
Description The token query interface ('/api/admin/sys-token/page') within the Token Management function of the System Management module suffers from insufficient permission verification. Any authenticated user can access this interface and retrieve plaintext authentication Tokens for all currently logged-in users, including administrators. This allows unauthorized users to obtain administrator Tokens, forge an administrator account, and gain full system management privileges, leading to system takeover.
Recommendations Versions prior to 3.8.2 should be updated.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-63691

Affected Products

Pig