CORS Misconfiguration in Vulnerable Web Applications by XYZ Corp
CVE-2025-25264

6.5MEDIUM

What is CVE-2025-25264?

A misconfiguration in the Cross-Origin Resource Sharing (CORS) policy in XYZ Corp's Web Application Suite enables unauthenticated remote attackers to exploit this weakness. This flaw permits attackers to access and read responses that may contain sensitive information. Consequently, the vulnerability may lead to further attacks, compromising user data and application integrity. Organizations using affected versions should prioritize remediation and enforce stricter CORS settings to safeguard against potential exploitation.

Affected Version(s)

CC100 0751-9x01 0.0.0 < 04.07.01 (FW29)

CC100 0751-9x01 0.0.0 < 04.07.01 (70

Edge Controller 0752-8303/8000-0002 0.0.0 < 04.07.01 (FW29)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-25264 : CORS Misconfiguration in Vulnerable Web Applications by XYZ Corp