CVE-2025-13477
Deferred Deferred - Pending Action

Authentication Bypass in WifiBurada via Credential Exposure

Vulnerability report for CVE-2025-13477, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-05-21

Last updated on: 2026-05-21

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026.Β NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-05-21
Last Modified
2026-05-21
Generated
2026-07-01
AI Q&A
2026-05-21
EPSS Evaluated
2026-06-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
digital_operations_services_inc wifiburada to 21052026 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-359 The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Digital Operations Services Inc. WifiBurada allows an unauthorized actor to bypass authentication due to insufficiently protected credentials. As a result, private personal information can be exposed to unauthorized individuals.

Compliance Impact

This vulnerability involves the exposure of private personal information to unauthorized actors and an authentication bypass due to insufficiently protected credentials in WifiBurada. Such exposure of personal data can lead to non-compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.

Specifically, GDPR mandates strict controls on personal data confidentiality and integrity, and breaches can result in significant penalties. Similarly, HIPAA requires protection of personal health information, and unauthorized exposure could violate its security rules.

Impact Analysis

The vulnerability can lead to exposure of private personal information to unauthorized actors. This means sensitive data could be accessed without permission, potentially leading to privacy breaches and misuse of personal information.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-13477. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart