Username Enumeration Vulnerability in Trivision NC-227WF Firmware
CVE-2025-56764
5.3MEDIUM
What is CVE-2025-56764?
The Trivision NC-227WF firmware version 5.80 (build 20141010) presents a significant security issue where the login mechanism offers varied error messages depending on the validity of the username entered. An attacker can exploit this flaw to determine which usernames are valid by triggering distinctive responses: 'Unknown user' when an invalid username is entered and 'Wrong password' for valid usernames with incorrect passwords. This behavior could lead to unauthorized access attempts and increase the risk of breaches as attackers can compile a list of valid usernames for further exploitation.
