CVE-2025-4526

A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15. This affects an unknown part of the component Configuration Page. The manipulation leads to missing password field masking. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.308271 Permissions Required VDB Entry
https://vuldb.com/?id.308271 Third Party Advisory VDB Entry
https://vuldb.com/?submit.565307 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:digitro:ngc_explorer:3.44.15:*:*:*:*:*:*:*

History

10 Nov 2025, 15:39

Type Values Removed Values Added
First Time Digitro
Digitro ngc Explorer
References () https://vuldb.com/?ctiid.308271 - () https://vuldb.com/?ctiid.308271 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.308271 - () https://vuldb.com/?id.308271 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.565307 - () https://vuldb.com/?submit.565307 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:digitro:ngc_explorer:3.44.15:*:*:*:*:*:*:*

Information

Published : 2025-05-11 01:15

Updated : 2025-11-10 15:39


NVD link : CVE-2025-4526

Mitre link : CVE-2025-4526

CVE.ORG link : CVE-2025-4526


JSON object : View

Products Affected

digitro

  • ngc_explorer
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-549

Missing Password Field Masking