CVE-2025-61166 is an open redirect vulnerability affecting Ascertia SigningHub User version 10.0, which allows attackers to redirect users to malicious websites through specially crafted URLs. An open redirect occurs when an application fails to properly validate redirect destinations, enabling attackers to trick users into visiting attacker-controlled sites. This vulnerability has a CVSS score of 6.1 (Medium severity) with a network-based attack vector requiring no privileges but necessitating user interaction, indicating moderate risk to affected organizations. The vulnerability is not currently tracked in the Known Exploited Vulnerabilities (KEV) catalog and shows minimal exploitation activity, with an exceptionally low EPSS score of 0.00027 suggesting limited real-world exploitation likelihood. Organizations using SigningHub User v10.0 should assess their exposure and apply available patches, though the low community attention and exploitation status suggest this is not an immediate critical threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.6.8CPE matchmatch criteria | cpe:2.3:a:ascertia:signinghub:8.6.8:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:ascertia:signinghub:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.