No analysis available yet.
Vendor Solution
The vulnerability has been fixed by the TESI team in version 4.4.2431.5.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23360 | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php. |
Fri, 01 Aug 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| References |
|
Fri, 01 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cryptographic vulnerability in Iridium Certus 700. This vulnerability allows a user to retrieve the encryption key, resulting in the loading of malicious firmware. | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php. |
| Title | Cryptographic vulnerability in Iridium Certus 700 | SQL injection vulnerability in Gandia Integra Total |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cryptographic vulnerability in Iridium Certus 700. This vulnerability allows a user to retrieve the encryption key, resulting in the loading of malicious firmware. | |
| Title | Cryptographic vulnerability in Iridium Certus 700 | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-08-01T12:30:09.665Z
Reserved: 2025-04-16T09:57:07.297Z
Link: CVE-2025-41377
Updated: 2025-05-27T14:39:31.780Z
Status : Deferred
Published: 2025-05-23T13:15:33.150
Modified: 2026-06-17T09:22:47.750
Link: CVE-2025-41377
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD