CVE-2025-29557
MEDIUMExaGrid EX10 6.3-7.0.1.P08 - Info Disclosure
Title source: llmDescription
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.
Exploits (1)
Scores
CVSS v3
5.4
EPSS
0.0006
EPSS Percentile
17.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Published
Jul 31, 2025
Tracked Since
Feb 18, 2026