CVE-2025-36845 describes a Server-Side Request Forgery (SSRF) vulnerability in Eveo URVE Web Manager version 27.02.2025. This flaw allows an attacker to manipulate the /_internal/redirect.php endpoint with a crafted URL, causing the application to send requests to internal or otherwise restricted network resources and reflect their content. The vulnerability carries a high CVSS score of 8.6, indicating a critical risk due to its network-based attack vector, low attack complexity, and high confidentiality impact, as it can expose sensitive internal information. Currently, there is no evidence of active exploitation, and no Metasploit modules or ExploitDB entries exist. However, Nuclei templates are available for detection, and despite a high FAUCET Risk Score, community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
27.02.2025CPE matchmatch criteria | cpe:2.3:a:eveo:urve_web_manager:27.02.2025:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.