Token Exposure Vulnerability in ESPEC North America Web Controller
CVE-2025-27845
9.8CRITICAL
What is CVE-2025-27845?
In prior versions of the ESPEC North America Web Controller, specifically before version 3.3.4, a security flaw exists in the authentication API endpoint (/api/v4/auth/). Invalid authentication requests can inadvertently reveal a JSON Web Token (JWT) secret. This exposure potentially grants unauthorized users elevated access privileges within the user interface, posing significant security risks to users and their data.
