CVE-2025-65185

There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.
Configurations

Configuration 1 (hide)

cpe:2.3:a:entrinsik:informer:5.10.1:*:*:*:*:*:*:*

History

05 Jan 2026, 15:06

Type Values Removed Values Added
References () https://entrinsik.com - () https://entrinsik.com - Product
References () https://www.triaxiomsecurity.com/entrinsik-informer-username-enumeration-cve-2025-65185/ - () https://www.triaxiomsecurity.com/entrinsik-informer-username-enumeration-cve-2025-65185/ - Exploit, Third Party Advisory
First Time Entrinsik informer
Entrinsik
CPE cpe:2.3:a:entrinsik:informer:5.10.1:*:*:*:*:*:*:*

05 Jan 2026, 07:15

Type Values Removed Values Added
References
  • {'url': 'http://entrinsik.com', 'source': 'cve@mitre.org'}
  • {'url': 'http://informer.com', 'source': 'cve@mitre.org'}
  • () https://entrinsik.com -

17 Dec 2025, 19:16

Type Values Removed Values Added
CWE CWE-203
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.8

17 Dec 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 17:15

Updated : 2026-01-05 15:06


NVD link : CVE-2025-65185

Mitre link : CVE-2025-65185

CVE.ORG link : CVE-2025-65185


JSON object : View

Products Affected

entrinsik

  • informer
CWE
CWE-203

Observable Discrepancy