CVE-2025-29557 Information

Description

ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials including plaintext passwords.

Reference

https://github.com/0xsu3ks/CVE-2025-29557 https://www.exagrid.com/

CNNVD-202507-3916 (Published: 2025-07-31)

Share on: