BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from storing credentials in a recoverable format. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25986.
History

Wed, 23 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
Description BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from storing credentials in a recoverable format. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25986.
Title BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability
Weaknesses CWE-256
References
Metrics cvssV3_0

{'score': 4.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2025-04-23T16:51:56.244Z

Updated: 2025-04-23T17:59:22.164Z

Reserved: 2025-03-24T19:44:24.105Z

Link: CVE-2025-2770

cve-icon Vulnrichment

Updated: 2025-04-23T17:59:17.998Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-23T17:16:55.027

Modified: 2025-04-29T13:52:47.470

Link: CVE-2025-2770

cve-icon Redhat

No data.