Security Advisory

CVE-2025-34156

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-23 16:30:41
Last updated 2026-05-14 02:07:48
Assigner VulnCheck
CVSS score 6.9
State PUBLISHED

Description

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.