CVE-2025-4526

A vulnerability was identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:digitro:ngc_explorer:3.44.15:*:*:*:*:*:*:*

History

27 May 2026, 15:16

Type Values Removed Values Added
References
  • {'url': 'https://vuldb.com/?ctiid.308271', 'tags': ['Permissions Required', 'VDB Entry'], 'source': 'cna@vuldb.com'}
  • {'url': 'https://vuldb.com/?id.308271', 'tags': ['Third Party Advisory', 'VDB Entry'], 'source': 'cna@vuldb.com'}
  • {'url': 'https://vuldb.com/?submit.565307', 'tags': ['Third Party Advisory', 'VDB Entry'], 'source': 'cna@vuldb.com'}
  • () https://digitro.com/recomendacao-10-2026-ctir-gov/ -
  • () https://vuldb.com/submit/565307 -
  • () https://vuldb.com/vuln/308271 -
  • () https://vuldb.com/vuln/308271/cti -
  • () https://www.gov.br/ctir/pt-br/assuntos/alertas-e-recomendacoes/recomendacoes/2026/recomendacao-10-2026 -
Summary (en) A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15. This affects an unknown part of the component Configuration Page. The manipulation leads to missing password field masking. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. (en) A vulnerability was identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure but did not respond in any way.

10 Nov 2025, 15:39

Type Values Removed Values Added
First Time Digitro ngc Explorer
Digitro
CPE cpe:2.3:a:digitro:ngc_explorer:3.44.15:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.308271 - () https://vuldb.com/?ctiid.308271 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.308271 - () https://vuldb.com/?id.308271 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.565307 - () https://vuldb.com/?submit.565307 - Third Party Advisory, VDB Entry

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad clasificada como problemática en Dígitro NGC Explorer 3.44.15. Esta afecta a una parte desconocida de la página de configuración del componente. La manipulación provoca la omisión del enmascaramiento del campo de contraseña. Es posible iniciar el ataque puede ejecutarse en remoto. Se contactó al proveedor con antelación para informarle sobre esta vulnerabilidad, pero no respondió.

11 May 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-11 01:15

Updated : 2026-05-27 15:16


NVD link : CVE-2025-4526

Mitre link : CVE-2025-4526

CVE.ORG link : CVE-2025-4526


JSON object : View

Products Affected

digitro

  • ngc_explorer
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-549

Missing Password Field Masking