Impact
The vulnerability is an Execution After Redirect flaw that lets attackers bypass authentication in FuyaWeb's ArchitectPanel Web Admin Panel. By manipulating the redirect logic, an attacker can gain unauthorized access to administrative functions, with the potential to modify configuration, exfiltrate data, or take control of the service. The defect is a logic error classified as CWE‑698, where the system incorrectly trusts a redirected request. Due to the lack of proper authentication regeneration after the redirect, the flaw results in a complete loss of access control. The CVSS score of 7.5 indicates a high severity, while the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. Nonetheless, the flaw can be triggered over the network through crafted web requests, making it a real threat to any installed instance until a patch or workaround is applied.
Affected Systems
Affected systems are installations of the FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel with versions up to and including Build 28072026; deployment of this component in any environment before this build would be susceptible to authentication bypass. The product is primarily used for web‑based management of network and application resources, and the flaw affects all users who rely on the standard login workflow. Users running this version must verify their deployment and plan remediation, as every instance of the panel remains exposed until remediated.
Risk and Exploitability
The CVSS score of 7.5 points to a high impact, and while the EPSS score is not available, the potential for exploitation is significant because the flaw is exploitable via a straightforward HTTP redirect manipulation. Attackers could reach the panel remotely, send a specially crafted request that triggers the redirect, and obtain authenticated access without providing valid credentials. Because the flaw is not yet in the KEV catalog, there is no confirmed exploit, but the logical nature of the weakness suggests that exploitation does not require advanced techniques, making the vulnerability a priority for swift mitigation.
OpenCVE Enrichment