---
id: CVE-2025-34156
title: >-
  Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information
  through an unauthenticated endpoint at /cwmp/happyaxis.jsp
summary: >-
  Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information
  through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses
  Java system properties, server path details, and version information to
  unautho…
severity: none
cwe:
  - CWE-497
published: '2025-10-23'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34156'
references:
  - url: 'https://aggregate.digital/downloads.html'
    label: disclosure@vulncheck.com
  - url: 'https://aggregate.digital/products/network-manager.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tibbo-aggregate-network-manager-system-information-exposure
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00371
epssPercentile: 0.28952
ingestedAt: '2026-10-08T11:31:27.560Z'
---

## Overview

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
