Insecure Communication Vulnerability in Kaleris NAVIS N4 Ultra Light Client
CVE-2025-5087

6MEDIUM

Key Information:

Vendor

Kaleris

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-5087?

Kaleris NAVIS N4 Ultra Light Client exhibits a serious security weakness due to its use of zlib-compressed data transmitted over HTTP. This insecure communication channel allows attackers to intercept network traffic between the Ultra Light Clients and N4 servers, potentially leading to the exposure of sensitive information such as plaintext user credentials. By exploiting this vulnerability, unauthorized individuals can gain access to critical data, posing significant risks to the integrity and confidentiality of user accounts.

Affected Version(s)

Navis N4 0 < 4.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-5087 : Insecure Communication Vulnerability in Kaleris NAVIS N4 Ultra Light Client