CORS Misconfiguration in Vulnerable Web Applications by XYZ Corp
CVE-2025-25264

8.8HIGH

What is CVE-2025-25264?

A misconfiguration in the Cross-Origin Resource Sharing (CORS) policy in XYZ Corp's Web Application Suite enables unauthenticated remote attackers to exploit this weakness. This flaw permits attackers to access and read responses that may contain sensitive information. Consequently, the vulnerability may lead to further attacks, compromising user data and application integrity. Organizations using affected versions should prioritize remediation and enforce stricter CORS settings to safeguard against potential exploitation.

Affected Version(s)

CC100 0751-9x01 0.0.0 < 04.07.01 (FW29)

CC100 0751-9x01 0.0.0 < 04.07.01 (70

Edge Controller 0752-8303/8000-0002 0.0.0 < 04.07.01 (FW29)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-25264 : CORS Misconfiguration in Vulnerable Web Applications by XYZ Corp