CVE-2025-54554

MEDIUM

Tera Insights tiCrypt <2025-07-17 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-54554. PoCs published by Aman-Parmar.

AI-analyzed exploit summary This repository contains a detailed technical writeup about CVE-2025-54554, an unauthenticated access vulnerability in the tiaudit REST API of the ticrypt platform, leading to sensitive information disclosure. The writeup includes the vulnerability's impact, affected components, and vendor response.

Description

tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

Exploits (1)

nomisec WRITEUP
by Aman-Parmar · poc
https://github.com/Aman-Parmar/CVE-2025-54554

This repository contains a detailed technical writeup about CVE-2025-54554, an unauthenticated access vulnerability in the tiaudit REST API of the ticrypt platform, leading to sensitive information disclosure. The writeup includes the vulnerability's impact, affected components, and vendor response.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ticrypt platform (tiaudit component)
No auth needed
Prerequisites: Access to the tiaudit REST API endpoints
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
Tera Insights/tiCrypt < 2025-07-17
Published Aug 04, 2025
Tracked Since Feb 18, 2026