CVE-2025-59108

CRITICAL

Access Manager - Info Disclosure

Title source: llm
STIX 2.1

Description

By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced.

Scores

CVSS v4 9.2
EPSS 0.0006
EPSS Percentile 17.9%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1392
Status published
Published Jan 26, 2026
Tracked Since Feb 18, 2026