CVE-2025-64387
BaseFortify
Publication date: 2025-10-31
Last updated on: 2025-11-04
Assigner: S21sec
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| circutor | tcprs1+ | 1.0.14 |
| circutor | myconfig | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1021 | The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a 'clickjacking' attack where an attacker embeds the vulnerable web page within a page they control. This tricks the victim into interacting with the embedded page unknowingly, such as clicking buttons or entering login credentials into a seemingly legitimate form.
How can this vulnerability impact me? :
The impact of this vulnerability includes the risk of unauthorized actions performed by the victim without their knowledge, such as clicking buttons or submitting sensitive information like login credentials, potentially leading to account compromise or unauthorized access.