Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-29557. PoCs published by 0xsu3ks.
AI-analyzed exploit summary CVE-2025-29557 is an information disclosure vulnerability in ExaGrid EX10 Backup Appliance versions 6.3 to 7.0.1.P08, where authenticated operator-level users can retrieve plaintext SMTP credentials via the MailConfiguration API.
Description
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.
Exploits (1)
CVE-2025-29557 is an information disclosure vulnerability in ExaGrid EX10 Backup Appliance versions 6.3 to 7.0.1.P08, where authenticated operator-level users can retrieve plaintext SMTP credentials via the MailConfiguration API.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N