Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9495

Опубликовано: 23 сент. 2025
Источник: nvd
EPSS Низкий

Описание

The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.

EPSS

Процентиль: 15%
0.00049
Низкий

Дефекты

CWE-602

Связанные уязвимости

github
5 месяцев назад

The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.

EPSS

Процентиль: 15%
0.00049
Низкий

Дефекты

CWE-602