CVE-2025-42602

HIGH

Meon KYC - Auth Bypass

Title source: llm
STIX 2.1

Description

This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints of authentication process. A remote attacker could exploit this vulnerability by intercepting and manipulating the responses through API request body leading to unauthorized access of other user accounts.

Scores

CVSS v4 8.2
EPSS 0.0056
EPSS Percentile 68.5%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-384 CWE-613
Status published
Products (1)
Meon/KYC solutions 1.1
Published Apr 23, 2025
Tracked Since Feb 18, 2026