From ccfba0f359ab030c734efa58b56c8048c6696785 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 9 Apr 2025 09:33:17 +0000 Subject: [PATCH] Publish Advisories GHSA-9hcv-xw76-m4h6 GHSA-72gj-xrp6-846v GHSA-766x-h993-jxjx GHSA-7w4r-qjmg-q6m9 GHSA-ch7j-r6cg-rfjc GHSA-cj66-fmhf-gpq3 GHSA-fcmv-663v-x4r8 GHSA-fw33-w47w-wxm4 GHSA-m3h9-x8gr-vfvr GHSA-vrc5-8xfg-g69r GHSA-xfj2-q583-73rv --- .../GHSA-9hcv-xw76-m4h6.json | 6 ++- .../GHSA-72gj-xrp6-846v.json | 36 +++++++++++++++++ .../GHSA-766x-h993-jxjx.json | 34 ++++++++++++++++ .../GHSA-7w4r-qjmg-q6m9.json | 40 +++++++++++++++++++ .../GHSA-ch7j-r6cg-rfjc.json | 40 +++++++++++++++++++ .../GHSA-cj66-fmhf-gpq3.json | 40 +++++++++++++++++++ .../GHSA-fcmv-663v-x4r8.json | 40 +++++++++++++++++++ .../GHSA-fw33-w47w-wxm4.json | 40 +++++++++++++++++++ .../GHSA-m3h9-x8gr-vfvr.json | 40 +++++++++++++++++++ .../GHSA-vrc5-8xfg-g69r.json | 40 +++++++++++++++++++ .../GHSA-xfj2-q583-73rv.json | 40 +++++++++++++++++++ 11 files changed, 395 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-72gj-xrp6-846v/GHSA-72gj-xrp6-846v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-766x-h993-jxjx/GHSA-766x-h993-jxjx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7w4r-qjmg-q6m9/GHSA-7w4r-qjmg-q6m9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ch7j-r6cg-rfjc/GHSA-ch7j-r6cg-rfjc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cj66-fmhf-gpq3/GHSA-cj66-fmhf-gpq3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fcmv-663v-x4r8/GHSA-fcmv-663v-x4r8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fw33-w47w-wxm4/GHSA-fw33-w47w-wxm4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m3h9-x8gr-vfvr/GHSA-m3h9-x8gr-vfvr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vrc5-8xfg-g69r/GHSA-vrc5-8xfg-g69r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xfj2-q583-73rv/GHSA-xfj2-q583-73rv.json diff --git a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json index 982053277f1..94d1bf139d7 100644 --- a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json +++ b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hcv-xw76-m4h6", - "modified": "2025-04-02T15:31:14Z", + "modified": "2025-04-09T09:31:24Z", "published": "2025-03-14T09:34:06Z", "aliases": [ "CVE-2024-8176" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:3531" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3734" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8176" diff --git a/advisories/unreviewed/2025/04/GHSA-72gj-xrp6-846v/GHSA-72gj-xrp6-846v.json b/advisories/unreviewed/2025/04/GHSA-72gj-xrp6-846v/GHSA-72gj-xrp6-846v.json new file mode 100644 index 00000000000..49538c0714f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-72gj-xrp6-846v/GHSA-72gj-xrp6-846v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72gj-xrp6-846v", + "modified": "2025-04-09T09:31:24Z", + "published": "2025-04-09T09:31:24Z", + "aliases": [ + "CVE-2025-3442" + ], + "details": "This vulnerability exists in TP-Link Tapo H200 V1 IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3442" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-766x-h993-jxjx/GHSA-766x-h993-jxjx.json b/advisories/unreviewed/2025/04/GHSA-766x-h993-jxjx/GHSA-766x-h993-jxjx.json new file mode 100644 index 00000000000..754bb763a63 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-766x-h993-jxjx/GHSA-766x-h993-jxjx.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-766x-h993-jxjx", + "modified": "2025-04-09T09:31:24Z", + "published": "2025-04-09T09:31:24Z", + "aliases": [ + "CVE-2025-20952" + ], + "details": "Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20952" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T08:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7w4r-qjmg-q6m9/GHSA-7w4r-qjmg-q6m9.json b/advisories/unreviewed/2025/04/GHSA-7w4r-qjmg-q6m9/GHSA-7w4r-qjmg-q6m9.json new file mode 100644 index 00000000000..c603d5f2936 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7w4r-qjmg-q6m9/GHSA-7w4r-qjmg-q6m9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w4r-qjmg-q6m9", + "modified": "2025-04-09T09:31:25Z", + "published": "2025-04-09T09:31:25Z", + "aliases": [ + "CVE-2025-27722" + ], + "details": "Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attack may allow a remote unauthenticated attacker to eavesdrop the communication and obtain the authentication information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27722" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ch7j-r6cg-rfjc/GHSA-ch7j-r6cg-rfjc.json b/advisories/unreviewed/2025/04/GHSA-ch7j-r6cg-rfjc/GHSA-ch7j-r6cg-rfjc.json new file mode 100644 index 00000000000..cbc32b4d209 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ch7j-r6cg-rfjc/GHSA-ch7j-r6cg-rfjc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch7j-r6cg-rfjc", + "modified": "2025-04-09T09:31:25Z", + "published": "2025-04-09T09:31:25Z", + "aliases": [ + "CVE-2025-25056" + ], + "details": "Cross-site request forgery vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views a malicious page while logged in, unintended operations may be performed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25056" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cj66-fmhf-gpq3/GHSA-cj66-fmhf-gpq3.json b/advisories/unreviewed/2025/04/GHSA-cj66-fmhf-gpq3/GHSA-cj66-fmhf-gpq3.json new file mode 100644 index 00000000000..c846bac931b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cj66-fmhf-gpq3/GHSA-cj66-fmhf-gpq3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj66-fmhf-gpq3", + "modified": "2025-04-09T09:31:25Z", + "published": "2025-04-09T09:31:25Z", + "aliases": [ + "CVE-2025-27934" + ], + "details": "Information disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product authentication information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27934" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fcmv-663v-x4r8/GHSA-fcmv-663v-x4r8.json b/advisories/unreviewed/2025/04/GHSA-fcmv-663v-x4r8/GHSA-fcmv-663v-x4r8.json new file mode 100644 index 00000000000..478a4c0c9a6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fcmv-663v-x4r8/GHSA-fcmv-663v-x4r8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcmv-663v-x4r8", + "modified": "2025-04-09T09:31:25Z", + "published": "2025-04-09T09:31:25Z", + "aliases": [ + "CVE-2025-29870" + ], + "details": "Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product configuration information including authentication information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29870" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fw33-w47w-wxm4/GHSA-fw33-w47w-wxm4.json b/advisories/unreviewed/2025/04/GHSA-fw33-w47w-wxm4/GHSA-fw33-w47w-wxm4.json new file mode 100644 index 00000000000..fee61f542d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fw33-w47w-wxm4/GHSA-fw33-w47w-wxm4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw33-w47w-wxm4", + "modified": "2025-04-09T09:31:25Z", + "published": "2025-04-09T09:31:25Z", + "aliases": [ + "CVE-2025-25213" + ], + "details": "Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the content on the malicious page while logged in, unintended operations may be performed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25213" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1021" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m3h9-x8gr-vfvr/GHSA-m3h9-x8gr-vfvr.json b/advisories/unreviewed/2025/04/GHSA-m3h9-x8gr-vfvr/GHSA-m3h9-x8gr-vfvr.json new file mode 100644 index 00000000000..8e6f92ce386 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m3h9-x8gr-vfvr/GHSA-m3h9-x8gr-vfvr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3h9-x8gr-vfvr", + "modified": "2025-04-09T09:31:25Z", + "published": "2025-04-09T09:31:25Z", + "aliases": [ + "CVE-2025-25053" + ], + "details": "OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25053" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vrc5-8xfg-g69r/GHSA-vrc5-8xfg-g69r.json b/advisories/unreviewed/2025/04/GHSA-vrc5-8xfg-g69r/GHSA-vrc5-8xfg-g69r.json new file mode 100644 index 00000000000..42f17c8b67b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vrc5-8xfg-g69r/GHSA-vrc5-8xfg-g69r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrc5-8xfg-g69r", + "modified": "2025-04-09T09:31:25Z", + "published": "2025-04-09T09:31:25Z", + "aliases": [ + "CVE-2025-27797" + ], + "details": "OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27797" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xfj2-q583-73rv/GHSA-xfj2-q583-73rv.json b/advisories/unreviewed/2025/04/GHSA-xfj2-q583-73rv/GHSA-xfj2-q583-73rv.json new file mode 100644 index 00000000000..4b57e81d421 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xfj2-q583-73rv/GHSA-xfj2-q583-73rv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfj2-q583-73rv", + "modified": "2025-04-09T09:31:24Z", + "published": "2025-04-09T09:31:24Z", + "aliases": [ + "CVE-2025-23407" + ], + "details": "Incorrect privilege assignment vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote attacker who can log in to the product may alter the settings without appropriate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23407" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93925742" + }, + { + "type": "WEB", + "url": "https://www.inaba.co.jp/abaniact/news/security_20250404.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T09:15:15Z" + } +} \ No newline at end of file