CVE-2025-25061

CVSS 3.0 Score 5.8 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 441

Summary

CVE-2025-25061 is a newly discovered vulnerability affecting the HMI ViewJet C-more series and HMI GC-A2 series. This issue involves an unintended proxy or intermediary problem, also known as a 'Confused Deputy' issue. An attacker can exploit this vulnerability remotely and without authentication to manipulate FTP traffic by using the affected product as an intermediary for bounce attacks. The implications of this flaw could lead to data theft or unauthorized access. It is crucial for organizations using these HMI systems to apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share