CVE-2025-58152
BaseFortify
Publication date: 2025-10-31
Last updated on: 2025-11-04
Assigner: JPCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in FutureNet MA and IP-K series devices by Century Systems Co., Ltd. The devices expose firmware version and garbage collection information on an internal web page. An attacker can craft specific HTTP requests to access this information without any authentication.
How can this vulnerability impact me? :
The vulnerability allows unauthenticated attackers to access sensitive device information such as firmware version and garbage collection data. This information disclosure could aid attackers in identifying device versions and potential weaknesses, possibly facilitating further attacks or exploitation.