{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-18T11:03:00.151","vulnerabilities":[{"cve":{"id":"CVE-2025-2771","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2025-04-23T17:16:55.160","lastModified":"2025-08-18T15:55:21.937","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the web-based user interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25894."},{"lang":"es","value":"Vulnerabilidad de omisión de autenticación en múltiples enrutadores de BEC Technologies. Esta vulnerabilidad permite a atacantes remotos omitir la autenticación en las instalaciones afectadas de enrutadores de BEC Technologies. No se requiere autenticación para explotar esta vulnerabilidad. La falla específica se encuentra en la interfaz de usuario web. El problema se debe a la falta de autenticación antes de permitir el acceso a la funcionalidad. Un atacante puede aprovechar esta vulnerabilidad para omitir la autenticación en el sistema. Anteriormente, se denominó ZDI-CAN-25894."}],"metrics":{"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:bectechnologies:router_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"0B67386D-1A8A-462E-B088-16742C92DA66"}]}]}],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-184/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]}]}}]}