CVE-2025-26001

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 26, 2025
Updated: Apr 1, 2025
CWE ID 200

Summary

CVE-2025-26001 is a newly disclosed vulnerability affecting the Telesquare TLR-2005KSH 1.1.4 system. This issue allows an attacker to gain unauthorized access to sensitive information through the getUserNamePassword parameter. By manipulating this input, an adversary can trigger an information disclosure event, potentially exposing confidential data. The exact nature and extent of the data that can be accessed remain unclear, but the vulnerability poses a significant risk to system security. It is essential that users of the Telesquare TLR-2005KSH 1.1.4 update their systems to the latest available patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share