Missing Password Field Masking in Dígitro NGC Explorer by Dígitro
CVE-2025-4526

5.3MEDIUM

Key Information:

Vendor

Dígitro

Vendor
CVE Published:
11 May 2025

What is CVE-2025-4526?

A serious vulnerability has been identified in the configuration page of Dígitro NGC Explorer version 3.44.15, which allows for a lack of password field masking. This flaw permits remote attackers to view passwords in plaintext, potentially exposing sensitive user data. Despite early notifications to the vendor regarding this issue, there has been no response, leaving users at risk of exploitation.

Affected Version(s)

NGC Explorer 3.44.15

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.