CVE-2025-41083
Unknown Unknown - Not Provided
Host Header Injection in Altitude Auth Service Enables Credential Phishing

Publication date: 2026-01-26

Last updated on: 2026-01-26

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-26
Last Modified
2026-01-26
Generated
2026-05-07
AI Q&A
2026-01-26
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
altitude altitude_authentication_service 8.5.3290.0
altitude altitude_communication_server 8.5.3290.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0. It involves manipulation of the Host header in HTTP requests, which allows an attacker to redirect users to an arbitrary URL or modify the base URL. This can trick victims into sending their login credentials to a malicious website controlled by the attacker.


How can this vulnerability impact me? :

The vulnerability can lead to users being redirected to attacker-controlled websites where their login credentials may be stolen. This can result in unauthorized access to user accounts and potential compromise of sensitive information.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart