CVE-2025-4526
A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15. This affects an unknown part of the component Configuration Page. The manipulation leads to missing password field masking. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.29%
- CWE
- CWE-549, CWE-200
- Published
- 2025-05-11
- Last modified
- 2026-07-31
Affected products
- Dígitro NGC Explorer
- Dígitro NGC Explorer
- Dígitro NGC Explorer
- Dígitro NGC Explorer
- Dígitro NGC Explorer
- Dígitro NGC Explorer
- Dígitro NGC Explorer
- Dígitro NGC Explorer
Weakness type
Related vulnerabilities
- CVE-2026-3314 — Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint
- CVE-2025-13175 — Insecure Password Storage in Y Soft SafeQ 6
- CVE-2025-42904 — Information Disclosure vulnerability in Application Server ABAP
- CVE-2025-64170 — sudo-rs: Partial password reveal is possible after timeout
- CVE-2025-0148 — Zoom Jenkins Marketplace plugin - Missing Password Field Masking
- CVE-2024-10122 — Topdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field masking
- CVE-2023-49106 — Missing Password Field Masking Vulnerability in Hitachi Device Manager
- CVE-2023-2062 — Information Disclosure vulnerability in EtherNet/IP Configuration tools