An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.
History

Mon, 16 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 10:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.
Title Overly Permissive CORS Policy in WAGO Device Manager
Weaknesses CWE-942
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2025-06-16T09:45:31.613Z

Updated: 2025-07-04T07:32:47.814Z

Reserved: 2025-02-06T12:30:08.317Z

Link: CVE-2025-25264

cve-icon Vulnrichment

Updated: 2025-06-16T18:15:53.456Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-16T10:15:19.517

Modified: 2025-06-16T12:32:18.840

Link: CVE-2025-25264

cve-icon Redhat

No data.