← back
CVE-2025-48463

Unencrypted HTTP Communication

CVSS 3.1 LOWEPSS 0.1%CWE-312
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.1EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
24 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses unencrypted HTTP communication, potentially leading to unauthorised access or data tampering.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →