CVE-2025-9004 is a critical vulnerability affecting mtons mblog up to version 3.5.0, stemming from improper restriction of excessive authentication attempts within the /settings/password file. With a CVSS score of 9.1, this remotely exploitable vulnerability has a high attack complexity but could lead to complete compromise of confidentiality and integrity. While public exploit disclosure exists, exploitation is considered difficult, and there is currently no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.5.0CPE matchmatch criteria | cpe:2.3:a:mtons:mblog:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.