CVE-2025-7426 - CVE House
Back to Database
Status published Critical CVE-2025-7426

MINOVA TTA Information Disclosure and Credential Exposure

Vulnerability Description

Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP server is part of automated business processes (e.g. EDI or data integration), this could lead to data manipulation, extraction, or abuse.  Debug ports 1602, 1603 and 1636 also expose service architecture information and system activity logs

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7426

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Stefan Mettler, Senior Penetration Tester from CRYPTRON Security GmbH
  • Jasmin Frei, Senior Project Manager from CRYPTRON Security GmbH

Affected Vendor

MINOVA Information Services GmbH

View all reports →

Affected Software

TTA
Vulnerable Versions:
11.17.0

Timeline

Official Publish: August 25th, 2025
Last Modified: August 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors