CVE-2025-24339

CVSS 3.1 Score 5 of 10 (medium)

Details

Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 644

Summary

CVE-2025-24339 is a newly disclosed vulnerability affecting the web application of ctrlX OS. This issue enables unauthenticated attackers to manipulate web caches or conduct Man-in-the-Middle (MitM) attacks by crafting malicious HTTP requests. Successful exploitation could lead to sensitive information disclosure, unauthorized system access, or even data modification. Users of the vulnerable system are advised to apply the necessary patches as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share