CVE-2025-2995 is a critical improper access control vulnerability in Tenda FH1202 firmware version 1.2.0.14(408). The issue affects the Web Management Interface, specifically the /goform/SysToolChangePwd endpoint. Based on the available information, insufficient access restrictions on this password-change functionality allow unauthorized remote interaction with the affected component. The exact vulnerable function or code path has not been disclosed, but the flaw is described as affecting unknown code within that endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) for CVE-2025-29927, an authorization bypass vulnerability in Next.js (versions 11 through 15.x). The repository contains a minimal Next.js application with a custom middleware (middleware.js) that checks for a specific Authorization header on all /api/* routes. The exploit leverages the 'x-middleware-subrequest' HTTP header to nest middleware invocations, which causes the authorization check to be bypassed, granting unauthorized access to protected endpoints such as /api/hello. The README.md provides detailed reproduction steps, including curl commands for both normal and exploitative requests, and explains how the exploit applies to different Next.js versions (with both middleware.js and _middleware.js naming conventions). The repository structure is typical for a Next.js app, with configuration files and a single middleware implementation. No fake or destructive code is present; the repository is focused on demonstrating the vulnerability and its exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.