CVE-2025-27910
CVSS 3.1 Score 8 of 10 (high)
Details
Summary
CVE-2025-27910 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability affecting the tianti v2.3 software. This issue, located in the /user/ajax/upd/status component, enables attackers to execute unauthorized and arbitrary operations by sending a specially crafted GET or POST request. Successful exploitation could result in significant impact, including the modification or destruction of data, unauthorized access, or unintended system behavior. Users are strongly encouraged to update their tianti installation to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.