CVE-2025-56015 is an unauthenticated access vulnerability affecting the NBI API endpoint in GenieACS version 1.2.13 and earlier. This flaw allows attackers to bypass authentication controls and access sensitive functionality without proper credentials. The vulnerability poses a significant confidentiality risk to organizations deploying this TR-069 auto-configuration management platform. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH), reflecting a critical severity level with no authentication required, low attack complexity, and network accessibility. While the attack does not permit modification of data or service disruption, it enables high-impact information disclosure to any unauthenticated remote attacker. The EPSS score of 0.000390000 indicates relatively low predicted exploitation probability compared to the broader vulnerability landscape. Currently, there is no evidence of active exploitation in the wild, as the vulnerability does not appear on the KEV catalog and is marked as inactive on threat intelligence hot lists. However, the straightforward attack vector and lack of authentication requirements warrant immediate patching, particularly for organizations with internet-facing GenieACS instances. Users should apply available security updates and implement network-level access controls to the NBI API endpoint as interim mitigations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.13CPE matchmatch criteria | cpe:2.3:a:genieacs:genieacs:1.2.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.