CVE-2025-42604
This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.46%
- CWE
- CWE-1295
- Published
- 2025-04-23
- Last modified
- 2026-03-13
Affected products
- Meon KYC solutions
Weakness type
Related vulnerabilities
- CVE-2026-28811 — Apache JSPWiki: Error Handling - Reveals Error Details
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2025-59109 — UART Leaking Sensitive Data in dormakaba registration unit 9002
- CVE-2025-46775 — A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0...
- CVE-2025-35031 — Medical Informatics Engineering Enterprise Health includes session token in debug output
- CVE-2025-2469 — Debug Messages Revealing Unnecessary Information in GitLab
- CVE-2025-31001 — WordPress GTM Kit plugin <= 2.4.0 - Sensitive Data Exposure vulnerability
- CVE-2025-2877 — Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda