CVE detail
CVE-2025-58584
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
Vendor Advisorywww.sick.comOct 6, 2025, 7:15 AMNo excerpt available.
Vendor Advisorywww.sick.comOct 6, 2025, 7:15 AMNo excerpt available.
Vendor Advisorywww.sick.comOct 6, 2025, 7:15 AM- https://www.first.org/cvss/calculator/3.1www.first.org
No excerpt available.
Not Applicablewww.first.orgOct 6, 2025, 7:15 AM No excerpt available.
Mitigationwww.cisa.govOct 6, 2025, 7:15 AM- https://sick.com/psirtsick.com
No excerpt available.
Vendor Advisorysick.comOct 6, 2025, 7:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-58587CVSS 6.5 · Medium
The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess us…
- CVE-2025-58586CVSS 5.3 · Medium
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This all…
- CVE-2025-58579CVSS 5.3 · Medium
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.
- CVE-2025-49184CVSS 7.5 · High
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.
- CVE-2025-9914CVSS 4.3 · Medium
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potential…
- CVE-2025-9913CVSS 4.5 · Medium
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.