CVE-2025-1595

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 23, 2025
CWE ID 284
CWE ID 200

Summary

CVE-2025-1595 is a newly disclosed vulnerability affecting Anhui Xufan Information Technology EasyCVR up to version 2.7.0. The issue, classified as problematic, lies in unknown code of the /api/v1/getbaseconfig file. Successful exploitation results in information disclosure, which can be initiated remotely. The exploit has been made public, increasing the risk of attacks. Despite early notification from security researchers, the vendor has not responded to address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share