CVE-2025-42601

HIGH

Meon KYC - Auth Bypass

Title source: llm
STIX 2.1

Description

This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this vulnerability by intercepting the request and removing the Captcha parameter leading to bypassing the Captcha verification mechanism.

Scores

CVSS v4 8.2
EPSS 0.0045
EPSS Percentile 63.6%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-602
Status published
Products (1)
Meon/KYC solutions 1.1
Published Apr 23, 2025
Tracked Since Feb 18, 2026