BEC Technologies Multiple Routers Insufficiently...
Moderate severity
Unreviewed
Published
Apr 23, 2025
to the GitHub Advisory Database
•
Updated Apr 23, 2025
Description
Published by the National Vulnerability Database
Apr 23, 2025
Published to the GitHub Advisory Database
Apr 23, 2025
Last updated
Apr 23, 2025
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.
References