---
id: CVE-2025-11284
title: >-
  A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central
  Authentication Service 3
summary: >-
  A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central
  Authentication Service 3. Affected by this vulnerability is an unknown
  functionality of the file /index.php/auth/Ops/git of the component HTTP Header
  Handler. The …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-255
  - CWE-259
published: '2025-10-05'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11284'
references:
  - url: >-
      http://101.200.76.102:38765/qwertyuiop/qwsdfvbnm/1/vuldb/fbnoABGFBEGPcvgmowepgokwj293t0-23t202jk9t0.html
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327042'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327042'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.659701'
    label: cna@vuldb.com
  - url: >-
      http://101.200.76.102:38765/qwertyuiop/qwsdfvbnm/1/vuldb/fbnoABGFBEGPcvgmowepgokwj293t0-23t202jk9t0.html
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0043
epssPercentile: 0.35176
ingestedAt: '2026-10-09T12:53:28.662Z'
---

## Overview

A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of hard-coded password. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
