CVE-2025-69270 is a critical information exposure vulnerability in Broadcom DX NetOps Spectrum versions 24.3.8 and earlier, affecting both Windows and Linux deployments. This flaw, categorized as CWE-598 (Information Exposure Through Query Strings in GET Request), allows for session hijacking due to sensitive data being exposed in GET request query strings. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk with high confidentiality, integrity, and availability impacts, requiring no user interaction or complex attack vectors. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, its high FAUCET Risk Score of 92/100 warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.3.9CPE matchmatch criteria | cpe:2.3:a:broadcom:dx_netops_spectrum:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.