- Description
- NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has been patched in version 25.4.14.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-306
- Hype score
- Not currently trending
🚨 CVE-2025-32440 ⚠️🔴 CRITICAL (10) 🏢 jokob-sk - NetAlertX 🏗️ < 25.4.14 🔗 https://t.co/6Ig5jW68N6 🔗 https://t.co/ih0Fx5wdjp #CyberCron #VulnAlert #InfoSec https://t.co/5yPD8ZPl8C
@cybercronai
29 May 2025
51 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Security Alert: CVE-2025-32440: CWE-306: Missing Authentication for Critical Function in jokob-sk NetAlertX (CVE-2025-32440) https://t.co/LcsOo5lcDt
@offseq
28 May 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-32440 NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update s… https://t.co/VQ6WGycVY0
@CVEnew
27 May 2025
579 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-32440: CRITICAL] NetAlertX addressed a critical security flaw in version 25.4.14, fixing authentication bypass. Attackers could manipulate util.php via crafted requests pre-update.#cve,CVE-2025-32440,#cybersecurity https://t.co/cz6j1yMfKq https://t.co/ATwK9VpdyD
@CveFindCom
27 May 2025
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netalertx:netalertx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "391ABCBA-1560-483B-B31A-3C66EF44D8D4",
"versionEndExcluding": "25.4.14"
}
],
"operator": "OR"
}
]
}
]