CVE-2025-65239: USSD Gateway Broken Access Control - Logs Description This vulnerability in the USSD Gateway application allows a low-privileged user to enumerate all trace/error log files, which should only be accessible by admin accounts. Application Details Name: USSD Gateway Vendor: OpenCode Systems Version: OC Release 5 - Version 6.13.11 Technical Details Vulnerable Endpoint "All files": Vulnerable Endpoint "Specific file": Exploitation The vulnerability allows a low-privileged user to enumerate trace and error log files as if they were an admin user. Example Request to Enumerate Log Files Example Request to Access Specific Log File