CVE-2025-52196

Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce the server to make arbitrary HTTP requests via a crafted HTML file containing an iframe.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ctera:ctera:8.1.1417.24:*:*:*:*:*:*:*

History

02 Jan 2026, 14:38

Type Values Removed Values Added
References () https://gist.github.com/simonecris/99baeb07fe6e1803d461e44031819cd3 - () https://gist.github.com/simonecris/99baeb07fe6e1803d461e44031819cd3 - Third Party Advisory
References () https://kb.ctera.com/docs/81x-portal - () https://kb.ctera.com/docs/81x-portal - Release Notes
First Time Ctera ctera
Ctera
CPE cpe:2.3:a:ctera:ctera:8.1.1417.24:*:*:*:*:*:*:*

17 Dec 2025, 15:15

Type Values Removed Values Added
CWE CWE-918
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

16 Dec 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 18:16

Updated : 2026-01-02 14:38


NVD link : CVE-2025-52196

Mitre link : CVE-2025-52196

CVE.ORG link : CVE-2025-52196


JSON object : View

Products Affected

ctera

  • ctera
CWE
CWE-918

Server-Side Request Forgery (SSRF)