Advisory Details

March 25th, 2025

(0Day) BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability

ZDI-25-185
ZDI-CAN-25895

CVE ID CVE-2025-2772
CVSS SCORE 5.3, AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AFFECTED VENDORS BEC Technologies
AFFECTED PRODUCTS Multiple Routers
VULNERABILITY DETAILS

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise.

ADDITIONAL DETAILS

12/06/24 – ZDI contacted the vendor’s support team via email
02/13/25 – ZDI requested an update
03/12/25 – ZDI informed the vendor that since we have not received a response, we will publish the report as a 0-day advisory


DISCLOSURE TIMELINE
  • 2025-03-11 - Vulnerability reported to vendor
  • 2025-03-25 - Coordinated public release of advisory
  • 2025-03-25 - Advisory Updated
CREDIT Steven C Yu of Trend Micro Research
BACK TO ADVISORIES