CVE 9.4 CRITICAL

EVMAPA Missing Authentication for Critical Function_CVE-2025-54816

9.4 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

This vulnerability occurs when a WebSocket endpoint does not enforce
proper authentication mechanisms, allowing unauthorized users to
establish connections. As a result, attackers can exploit this weakness
to gain unauthorized access to sensitive data or perform unauthorized
actions. Given that no authentication is required, this can lead to
privilege escalation and potentially compromise the security of the
entire system.

Basic Information

ID CVE-2025-54816
Source icscert
Published Jan 22, 2026 at 22:40
Modified Jan 23, 2026 at 20:12

Affected Product

Vendor EVMAPA
Product EVMAPA
Version All versions
Affected Versions EVMAPA EVMAPA All versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.