NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has been patched in version 25.4.14.
Metrics
Affected Vendors & Products
References
History
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netalertx
Netalertx netalertx |
|
CPEs | cpe:2.3:a:netalertx:netalertx:*:*:*:*:*:*:*:* | |
Vendors & Products |
Netalertx
Netalertx netalertx |
Wed, 28 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 27 May 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has been patched in version 25.4.14. | |
Title | NetAlertX Vulnerable to Authentication Bypass | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-27T21:59:40.497Z
Updated: 2025-05-28T13:45:52.417Z
Reserved: 2025-04-08T10:54:58.369Z
Link: CVE-2025-32440

Updated: 2025-05-28T13:45:44.169Z

Status : Analyzed
Published: 2025-05-27T22:15:21.980
Modified: 2025-07-11T18:58:26.233
Link: CVE-2025-32440

No data.