Open Redirection Vulnerability in Kiwire Captive Portal
CVE-2025-11190

Currently unrated

Key Information:

Vendor

Synchroweb

Status
Vendor
CVE Published:
10 October 2025

What is CVE-2025-11190?

The Kiwire Captive Portal is vulnerable to an open redirection flaw through the login-url parameter. This vulnerability enables attackers to manipulate the login process, redirecting users to malicious sites that they control, potentially exposing sensitive information or compromising user security.

Affected Version(s)

Kiwire 3.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11190 : Open Redirection Vulnerability in Kiwire Captive Portal