Sensitive Information Exposure on CIRCUTOR Web Server
CVE-2025-64386 
7.7HIGH
What is CVE-2025-64386?
This vulnerability allows sensitive information to be transmitted unencrypted through the web server of CIRCUTOR devices. As a result, attackers may intercept and access confidential data during communication, highlighting the need for proper encryption protocols to safeguard data integrity.
Affected Version(s)
TCPRS1plus 1.0.14
References
CVSS V4
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
 High
Availability:
 High
Attack Vector:
Network
Attack Complexity:
 High
Attack Required:
 None
Privileges Required:
 Undefined
User Interaction:
 Unknown
Timeline
- Vulnerability published 
- Vulnerability Reserved 
Credit
VĂctor Bello Cuevas
Aarón Flecha Menéndez
