Impact
The vulnerability resides in the Customer Information API's /customer-currency/ component of Omega Solution:CoinEx Crypto 2025. Manipulating the ID parameter allows an attacker to bypass normal authorization checks, gaining unauthorized access to customer currency data. This issue is classified as an authorization bypass; the attacker can obtain or modify data that should be protected. The vulnerability is identified as CWE-285 and CWE-639.
Affected Systems
Omega Solution's CoinEx Crypto platform, version 2025. The specific affected module is the customer-currency endpoint of the Customer Information API. The product has been discontinued or replaced and the vendor's website no longer exists, making upgrade paths unclear.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, but publicly available exploit code suggests the risk is real. The vulnerability is usable remotely through the API, and no remediation is currently published. It is not listed in the CISA KEV catalog, but due to the public exploit and remote nature it should be treated with urgency.
OpenCVE Enrichment