THREAT OPS › Threat News › [NVD] CVE-2025-4526 (MEDIUM 4.3) — A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.4
[NVD] CVE-2025-4526 (MEDIUM 4.3) — A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.4
CVE-2025-4526 CVSS: 4.3 MEDIUM Published: 2025-05-11T01:15:52.000
A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue. It is suggested
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2025-4526cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-4526