CVE-2025-57434

Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what follows.
Configurations

Configuration 1 (hide)

cpe:2.3:a:creacast:creabox_manager:4.4.4:*:*:*:*:*:*:*

History

14 Oct 2025, 19:56

Type Values Removed Values Added
First Time Creacast creabox Manager
Creacast
References () http://www.creacast.com/ - () http://www.creacast.com/ - Product
References () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-57434 - () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-57434 - Exploit, Third Party Advisory
CPE cpe:2.3:a:creacast:creabox_manager:4.4.4:*:*:*:*:*:*:*

22 Sep 2025, 18:15

Type Values Removed Values Added
CWE CWE-798
CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

22 Sep 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 17:16

Updated : 2025-10-14 19:56


NVD link : CVE-2025-57434

Mitre link : CVE-2025-57434

CVE.ORG link : CVE-2025-57434


JSON object : View

Products Affected

creacast

  • creabox_manager
CWE
CWE-287

Improper Authentication

CWE-798

Use of Hard-coded Credentials