CVE-2025-4130
BaseFortify
Publication date: 2025-07-21
Last updated on: 2025-07-22
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pavo | pavo_pay | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the use of hard-coded credentials in the PAVO Pay software by PAVO Inc. Specifically, it allows an attacker to read sensitive constants within the executable, which could expose confidential information embedded in the software.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive information due to the exposure of hard-coded credentials. This could allow attackers to gain unauthorized access or compromise the security of the affected system, potentially leading to data breaches or other security incidents.