← All CVEs

CVE-2023-25437

high · 8.8

An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML.

8.8
CVSS
14.1%
EPSS (exploit prob.)
96th
EPSS percentile
2023-04-27
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-319

Affected products

VendorProductAffected versions
vtechvcs754a_firmware>= 1.1.1.a, < 1.1.1.h
vtechvcs754aall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-25437