CVE-2025-51054 Information

Description

Vedo Suite 2024.17 is vulnerable to Incorrect Access Control which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST request to the /autologin/ API endpoint.

Reference

http://bottinelli.com https://github.com/jacopoaugelli/vedo-suite-exploits

CNNVD-202508-628 (Published: 2025-08-06)

Share on: