CVE-2025-13477
Deferred Deferred - Pending Action
Authentication Bypass in WifiBurada via Credential Exposure

Publication date: 2026-05-21

Last updated on: 2026-05-21

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026.Β NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-21
Last Modified
2026-05-21
Generated
2026-06-10
AI Q&A
2026-05-21
EPSS Evaluated
2026-06-09
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
digital_operations_services_inc wifiburada to 21052026 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-359 The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

This vulnerability involves the exposure of private personal information to unauthorized actors and an authentication bypass due to insufficiently protected credentials in WifiBurada. Such exposure of personal data can lead to non-compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.

Specifically, GDPR mandates strict controls on personal data confidentiality and integrity, and breaches can result in significant penalties. Similarly, HIPAA requires protection of personal health information, and unauthorized exposure could violate its security rules.

Executive Summary

This vulnerability in Digital Operations Services Inc. WifiBurada allows an unauthorized actor to bypass authentication due to insufficiently protected credentials. As a result, private personal information can be exposed to unauthorized individuals.

Impact Analysis

The vulnerability can lead to exposure of private personal information to unauthorized actors. This means sensitive data could be accessed without permission, potentially leading to privacy breaches and misuse of personal information.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-13477. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart