CVE-2025-0674

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 288

Summary

CVE-2025-0674 is a vulnerability affecting multiple Elber products. It involves an authentication bypass issue that enables unauthorized access to password management functionality. Attackers can exploit this flaw by manipulating the endpoint, allowing them to overwrite any user's password within the system. This vulnerability grants unauthorized administrative access to protected areas of the application, posing a significant risk to the device's system security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share