PT-2025-48188 · Unknown · Revive Adserver

Kassem S

·

Published

2025-11-26

·

Updated

2025-12-30

·

CVE-2025-55129

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Revive Adserver (affected versions not specified)
Description The software contains a flaw in username validation that allows anyone to register look-alike accounts and impersonate administrators. This issue persists after a previous fix for CVE-2025-52672, with impersonation possible through several alternate techniques, including homoglyphs. The vulnerability could indirectly impact over 1–10 million users through ad-delivery chains across thousands of installations worldwide. The issue involves handling of usernames, potentially allowing malicious actors to create accounts that visually resemble legitimate administrator accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2025-55129

Affected Products

Revive Adserver