Impact
A flaw in ESAFENET CDG allows manipulation of the keyid argument in the /CDGServer3/ukey/usbkey;logindojojs function, enabling attackers to inject unsanitized SQL statements. This can compromise database integrity or confidentiality, potentially leading to unauthorized data retrieval or modification.
Affected Systems
ESAFENET CDG products prior to the build dated 20260615 are affected. The vulnerability resides in the /CDGServer3/ukey/usbkey;logindojojs interface, and the specific function is not enumerated. No alternative versions are specified, so all releases up to that date are susceptible.
Risk and Exploitability
The assessed CVSS score of 6.9 indicates moderate risk. EPSS is not available, and the vulnerability has not been listed in the CISA KEV catalog. Because the flaw is exploitable remotely and publicly available exploits exist, adversaries can potentially drive unauthorized SQL queries against the backend database. The lack of a vendor response heightens the risk that affected installations remain exposed.
OpenCVE Enrichment