CVE-2025-13480 is an access control vulnerability affecting Fudo Enterprise versions 5.5.0 through 5.6.2, in which low-privileged users can bypass authorization controls to access administrator-only API endpoints and retrieve sensitive data including system logs and configuration settings. The vulnerability stems from improper protection of API endpoints and has been remediated in version 5.6.3. The attack vector appears to be network-based with low complexity, allowing authenticated but unprivileged users to escalate access and obtain confidential information. While a formal CVSS score is unavailable, the FAUCET Risk Score of 40.0 out of 100 indicates moderate concern, though the extremely low EPSS score of 0.00018 suggests minimal real-world exploitation probability. This vulnerability is not currently being exploited in the wild, as evidenced by its absence from the Known Exploited Vulnerabilities catalog and inactive status on threat intelligence hotlists. No public exploit code has been identified, and community attention remains limited. Organizations running affected versions should prioritize updating to 5.6.3 to eliminate this access control weakness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.5.0, < 5.6.3CPE matchmatch criteria | cpe:2.3:a:fudosecurity:fudo_enterprise:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.