CVE-2025-12461 - CVE House
Back to Database
Status published Medium CVE-2025-12461

Unprotected access to parts of the application in Epsilon RH by Grupo Castilla

Vulnerability Description

This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12461

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Oscar Atienza

Affected Vendor

Grupo Castilla

View all reports →

Affected Software

Epsilon RH
Vulnerable Versions:
3.03.36.0185

Timeline

Official Publish: October 29th, 2025
Last Modified: October 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)