CVE-2025-25711

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 12, 2025
CWE ID 281

Summary

CVE-2025-25711 is a vulnerability affecting dtp.ae tNexus Airport View version 2.8. An attacker can exploit this issue by manipulating the ProfileID value in a remote request, allowing them to escalate privileges and gain unauthorized access to the [tnexus/rest/admin/updateUser] API endpoint. This vulnerability poses a significant risk for unauthorized system modifications and unintended data exposure. Organizations using the affected version of tNexus Airport View are advised to apply the necessary patches or upgrades as soon as possible to mitigate this privilege escalation threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share