Unprotected Access Vulnerability in Epsilon RH by Grupo Castilla
CVE-2025-12461

6.9MEDIUM

Key Information:

Vendor
CVE Published:
29 October 2025

What is CVE-2025-12461?

This vulnerability enables attackers to gain unauthorized access to sensitive information within the Epsilon RH application. By exploiting the lack of access controls, an attacker can directly access certain components of the application, such as the '/epsilonnet/License/About.aspx' path, revealing confidential license and configuration details. Knowing which modules are installed allows them to glean crucial information, putting both the product and its users at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Epsilon RH 3.03.36.0185

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oscar Atienza
.