The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login credentials in a form that, a priori, appears legitimate.
Advisories

No advisories yet.

Fixes

Solution

The new version of the device will use the HTTPS protocol.


Workaround

No workaround given by the vendor.

History

Fri, 31 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 14:30:00 +0000

Type Values Removed Values Added
Description The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login credentials in a form that, a priori, appears legitimate.
Title CLICKJACKING
Weaknesses CWE-1021
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: S21sec

Published:

Updated: 2025-10-31T14:39:38.610Z

Reserved: 2025-10-31T13:13:35.299Z

Link: CVE-2025-64387

cve-icon Vulnrichment

Updated: 2025-10-31T14:38:11.065Z

cve-icon NVD

Status : Received

Published: 2025-10-31T15:15:43.773

Modified: 2025-10-31T15:15:43.773

Link: CVE-2025-64387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.