CVE-2025-2772

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 59

Summary

CVE-2025-2772 is a vulnerability affecting BEC Technologies routers, where insufficient protection of credentials information leads to disclosure. Attackers, without requiring authentication, can exploit this issue by targeting the /cgi-bin/tools_usermanage.asp page. The vulnerability exposes transported credentials, increasing the risk of further compromise. This security flaw was identified as ZDI-CAN-25895.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft