CVE-2023-25437

HIGH

vTech VCS754A Firmware 1.1.1.A-1.1.1.H - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML.

Scores

CVSS v3 8.8
EPSS 0.1411
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-319
Status published
Products (1)
vtech/vcs754a_firmware 1.1.1.a - 1.1.1.h
Published Apr 27, 2023
Tracked Since Feb 18, 2026