CVE-2025-13926
Last modified
CVE-2025-13926 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Contemporary Controls | BASControl20 | 3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-13926?
How severe is CVE-2025-13926?
How do I fix CVE-2025-13926?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13920The WP Directory Kit plugin for WordPress is vulnerable to S…5.3
- CVE-2025-13921The weDocs: AI Powered Knowledge Base, Docs, Documentation, …4.3
- CVE-2025-13922The Tag, Category, and Taxonomy Manager – AI Autotagger with…6.5
- CVE-2025-13923Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-13924The Advanced Product Fields (Product Addons) for WooCommerce…4.3
- CVE-2025-13925IBM Aspera Console 3.4.7 stores potentially sensitive inform…4.9
- CVE-2025-13927GitLab has remediated an issue in GitLab CE/EE affecting all…7.5
- CVE-2025-13928GitLab has remediated an issue in GitLab CE/EE affecting all…7.5
- CVE-2025-13929GitLab has remediated an issue in GitLab CE/EE affecting all…7.5
- CVE-2025-1393An unauthenticated remote attacker can use hard-coded creden…9.8
- CVE-2025-13930The Checkout Field Manager (Checkout Manager) for WooCommerc…5.3
- CVE-2025-13932The SolisCloud API suffers from a Broken Access Control vuln…8.3
Are you affected by CVE-2025-13926?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
