Improper Error Handling in Quiter Gateway by Quiter
CVE-2025-40718

6.9MEDIUM

Key Information:

Vendor

Quiter

Vendor
CVE Published:
8 July 2025

What is CVE-2025-40718?

An improper error handling vulnerability exists in Quiter Gateway, allowing attackers to exploit versions prior to 4.7.0. By sending malformed payloads, they can generate error messages that may inadvertently expose sensitive information. This could potentially lead to unauthorized access or data leaks, posing a significant risk to users of the affected software.

Affected Version(s)

Quiter Gateway (Java WAR on Apache Tomcat) 0 < 4.7.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David CarriĂłn Poza
.