NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has been patched in version 25.4.14.
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 27 May 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has been patched in version 25.4.14. | |
Title | NetAlertX Vulnerable to Authentication Bypass | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-27T21:59:40.497Z
Updated: 2025-05-28T13:45:52.417Z
Reserved: 2025-04-08T10:54:58.369Z
Link: CVE-2025-32440

Updated: 2025-05-28T13:45:44.169Z

Status : Awaiting Analysis
Published: 2025-05-27T22:15:21.980
Modified: 2025-05-28T15:01:30.720
Link: CVE-2025-32440

No data.