Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-27845

EPSS 0.11% · P29
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-27845

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ESPEC North America Web Controller 3 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ESPEC North America Web Controller 3是美国ESPEC North America公司的一个实验室设备监控软件。 ESPEC North America Web Controller 3 3.3.4之前版本存在安全漏洞,该漏洞源于无效认证请求导致JWT密钥泄露,可能导致UI权限提升。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-27845

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-27845

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-08-14 · 23 CVEs total

CVE-2025-87148.8 HIGHPostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
CVE-2025-87158.8 HIGHPostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in re
CVE-2025-89613.3 LOWLibTIFF tiffcrop tiffcrop.c main memory corruption
CVE-2025-87133.1 LOWPostgreSQL optimizer statistics can expose sampled data within a view, partition, or child
CVE-2025-51965OURPHP 安全漏洞
CVE-2025-50862Altus Cars Lotus Cars Android app 安全漏洞
CVE-2025-50861Altus Cars Lotus Cars Android app 安全漏洞
CVE-2025-52335EyouCMS 安全漏洞
CVE-2025-51986SILA Embedded Solutions Freemodbus 安全漏洞
CVE-2025-50817python-future 安全漏洞
CVE-2023-43687Malwarebytes 安全漏洞
CVE-2025-50515EmpireSoft Empirebak 安全漏洞
CVE-2023-43683Malwarebytes 安全漏洞
CVE-2023-43692Malwarebytes 安全漏洞
CVE-2025-50518libcoap 安全漏洞
CVE-2023-43694Malwarebytes 安全漏洞
CVE-2025-27847ESPEC North America Web Controller 3 安全漏洞
CVE-2025-27846ESPEC North America Web Controller 3 安全漏洞
CVE-2025-43983KuWFi CPF908-CP5 安全漏洞
CVE-2024-53946KuWFi 4G LTE AC900 安全漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-27845

No comments yet


Leave a comment