Secret leak with wwwdnload.cgi
Vulnerability Description
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41762
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Adrien Rey from Cyber Defense Campus Zurich
- Daniel Hulliger from Armasuisse
References
More from MBS
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.