CVE-2025-5485
HIGHDescription
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from known identifiers or through enumerating random digit sequences.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-5485? +
How severe is CVE-2025-5485? +
How do I check if I'm vulnerable to CVE-2025-5485? +
Related Vulnerabilities
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well …
IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the …
Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based …
User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker …
An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
CWE-204: Observable Response Discrepancy