Improper Authentication Vulnerability in roncoo-pay by roncoo
CVE-2025-10288

6.9MEDIUM

Key Information:

Vendor

Roncoo

Vendor
CVE Published:
12 September 2025

What is CVE-2025-10288?

A vulnerability has been identified in roncoo-pay that allows an attacker to perform improper authentication through manipulation of functions within the /user/info/list file. This flaw enables remote exploitation, posing a significant security risk. Despite the vendor being notified about this issue, there has been no response regarding potential fixes or updates. Therefore, users are urged to exercise caution when using affected versions of the product.

Affected Version(s)

roncoo-pay 9428382af21cd5568319eae7429b7e1d0332ff40

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

aibot88 (VulDB User)
.