CVE-2025-2125 is a problematic vulnerability affecting Control iD RH iD version 25.2.25.0. Specifically, it involves improper control of resource identifiers within the PDF Document Handler component when processing the 'nsr' argument in the /v2/report.svc/comprovante_marcacao/ endpoint. Rated with a CVSS score of 4.3 (Medium), this vulnerability can be exploited remotely with low attack complexity and requires low privileges, potentially leading to a limited disclosure of information. There is no indication of impact on integrity or availability. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. The vendor did not respond to early disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
25.2.25.0CPE matchmatch criteria | cpe:2.3:a:assaabloy:control_id_rhid:25.2.25.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.