CVE-2025-34156

MEDIUM

Tibbo AggreGate Network Manager < 6.40.05 - Info Disclosure

Title source: llm
STIX 2.1

Description

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.

Scores

CVSS v4 6.9
EPSS 0.0006
EPSS Percentile 17.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
Tibbo Systems/AggreGate Network Manager < 6.40.05
Published Oct 23, 2025
Tracked Since Feb 18, 2026