Access Control Vulnerability in brcc Product by Baidu
CVE-2025-45616

9.8CRITICAL

Key Information:

Vendor

Baidu

Status
Vendor
CVE Published:
5 May 2025

What is CVE-2025-45616?

A significant security issue has been identified in the brcc product version 1.2.0 by Baidu, where improper access control in the /admin/ API allows attackers to gain unauthorized admin rights through carefully crafted requests. This vulnerability emphasizes the importance of robust access control measures to protect sensitive administrative functionalities from exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-45616 : Access Control Vulnerability in brcc Product by Baidu