CVE-2025-7426

Published Aug 25, 2025 Modified Apr 15, 2026 CWE-200 CWE-312 CWE-532

Description

Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP server is part of automated business processes (e.g. EDI or data integration), this could lead to data manipulation, extraction, or abuse.  Debug ports 1602, 1603 and 1636 also expose service architecture information and system activity logs

Is your site exposed to CVE-2025-7426?

Run a free security scan — no signup, results in seconds.

Weakness Type (CWE)

CWE-200 CWE-200
CWE-312 CWE-312
CWE-532 CWE-532

References

Frequently Asked Questions

What is CVE-2025-7426? +
Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP server is part of automated business processes (e.g. EDI or data integration), this could lead to data manipulation, extraction, or abuse.  Debug ports 1602, 1603 and 1636 also expose service architecture information and system activity logs
How do I check if I'm vulnerable to CVE-2025-7426? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-7426 — free, no signup required.