CVE-2025-2772
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 59
Summary
CVE-2025-2772 is a vulnerability affecting BEC Technologies routers, where insufficient protection of credentials information leads to disclosure. Attackers, without requiring authentication, can exploit this issue by targeting the /cgi-bin/tools_usermanage.asp page. The vulnerability exposes transported credentials, increasing the risk of further compromise. This security flaw was identified as ZDI-CAN-25895.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft