Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-56764. PoCs published by Remenis.
AI-analyzed exploit summary This repository documents CVE-2025-56764, a username enumeration vulnerability in Trivision NC-227WF firmware 5.80 due to differential error messages during login attempts. It provides details on observed behavior, impact, and mitigation recommendations.
Description
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.
Exploits (1)
This repository documents CVE-2025-56764, a username enumeration vulnerability in Trivision NC-227WF firmware 5.80 due to differential error messages during login attempts. It provides details on observed behavior, impact, and mitigation recommendations.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N