CVE-2025-0556
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.31%
- CWE
- CWE-319
- Published
- 2025-02-12
- Last modified
- 2026-03-13
Affected products
- Progress Software Telerik Report Server
Weakness type
Related vulnerabilities
- CVE-2026-81330 — Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
- CVE-2026-87482 — Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to...
- CVE-2026-71216 — Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
- CVE-2026-84381 — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
- CVE-2026-84366 — Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
- CVE-2026-55860 — MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
- CVE-2026-55857 — MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
- CVE-2026-55854 — MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb