5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to import the appliance configuration, allowing an attacker to control the configuration of the appliance, to include granting themselves administrative level permissions.
Basic Information
ID
CVE-2025-54765
Source
KoreLogic
Published
Jul 28, 2025 at 23:25
Modified
Jul 29, 2025 at 13:30
Affected Product
Vendor
Xorux
Product
XorMon-NG
Version
1.8
Affected Versions
Xorux XorMon-NG 1.8