CVE-2025-34180None▾ SunlitNetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file can decode the stored value to recover the plaintext Gateway Key. Possession of the Gateway Key allows unauthorized access to NetSupport Manager connectivity services and enables remote control of systems managed through the same key.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-0280High· 7.5A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
CVE-2025-8095NoneThe OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform
CVE-2025-8307NoneAsseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector
CVE-2026-103548Medium· 5.3Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.
CVE-2025-58049Medium· 5.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it
CVE-2026-69297Medium· 6.5Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.