CVE-2025-32352

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 5, 2025
Updated: Apr 7, 2025
CWE ID 843

Summary

CVE-2025-32352 is a type confusion vulnerability identified in ZendTo's lib/NSSAuthenticator.php file, prior to version 5.04-7. This issue enables remote attackers to bypass authentication for MD5-hashed passwords that can be misinterpreted as numbers. The vulnerability arises due to a type confusion error. Affected users are advised to upgrade to a version that employs bcrypt instead of MD5 for password hashing to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share