CVE-2025-57430

Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:creacast:creabox_manager:4.4.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-22 16:15

Updated : 2025-10-14 19:57


NVD link : CVE-2025-57430

Mitre link : CVE-2025-57430

CVE.ORG link : CVE-2025-57430


JSON object : View

Products Affected

creacast

  • creabox_manager
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor