ETQ Reliance CG/NXG API Authorization Bypass via ;localized-text URI Suffix
Vulnerability Description
An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34140
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Adam Kues and Shubham Shah of Assetnote