A low-privileged remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://certvde.com/en/advisories/VDE-2025-018/ |
![]() ![]() |
History
Mon, 06 Oct 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks. | A low-privileged remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks. |
Mon, 16 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 16 Jun 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks. | |
Title | Overly Permissive CORS Policy in WAGO Device Manager | |
Weaknesses | CWE-942 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-06-16T09:45:31.613Z
Updated: 2025-10-07T07:16:37.653Z
Reserved: 2025-02-06T12:30:08.317Z
Link: CVE-2025-25264

Updated: 2025-06-16T18:15:53.456Z

Status : Awaiting Analysis
Published: 2025-06-16T10:15:19.517
Modified: 2025-10-07T08:15:35.103
Link: CVE-2025-25264

No data.