# CVE-2025-54766

## Summary

- **CVE ID:** CVE-2025-54766
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-648
- **Published:** Jul 28, 2025
- **Last Modified:** Mar 12, 2026

## Description

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to export the appliance configuration, exposing sensitive information.

## Affected Products

- Xorux — XorMon-NG (1.8)

## References

- [CNA](https://korelogic.com/Resources/Advisories/KL-001-2025-012.txt)
- [CNA](https://xormon.com/note190.php)
- [CVE](http://seclists.org/fulldisclosure/2025/Jul/15)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 7.58%
- **EPSS Percentile:** 94.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._