CVE-2025-36754
Last modified
CVE-2025-36754 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-36754?
How severe is CVE-2025-36754?
How do I fix CVE-2025-36754?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-36748ShineLan-X contains a stored cross site scripting (XSS) vuln…5.4
- CVE-2025-3675A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20…5.3
- CVE-2025-36750ShineLan-X contains a stored cross site scripting (XSS) vuln…5.4
- CVE-2025-36751Encryption is missing on the configuration interface for Gro…9.4
- CVE-2025-36752Growatt ShineLan-X communication dongle has an undocumented …9.8
- CVE-2025-36753The SWD debug interface on the Growatt ShineLan-X communicat…9.8
- CVE-2025-36755The CleverDisplay BlueOne hardware player is designed with i…2.4
- CVE-2025-36756A problem with missing authorization on SolaX Cloud platform…5.8
- CVE-2025-36757It is possible to bypass the administrator login screen on S…6.3
- CVE-2025-36758It is possible to bypass the clipping level of authenticatio…6.3
- CVE-2025-36759Through the provision of user names, SolaX Cloud will sugges…8.7
- CVE-2025-3676A vulnerability classified as critical has been found in xxy…9.8
Are you affected by CVE-2025-36754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
