CVE 6 MEDIUM

Weak encryption on Funambol’s cloud server_CVE-2025-41351

6 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate β€˜self-signed’ access URLs.

Basic Information

ID CVE-2025-41351
Source INCIBE
Published Jan 28, 2026 at 10:43

Affected Product

Vendor Funambol
Product Cloud Server
Version 30.0.0.20
Affected Versions Funambol Cloud Server 30.0.0.20

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.