CVE-2025-24876 is an authentication bypass vulnerability affecting SAP Approuter Node.js package versions up to and including v16.7.1. An attacker can exploit this by injecting malicious payloads during authorization code trading, allowing them to steal a victim's session. This vulnerability carries a high CVSS score of 8.1, indicating significant impact on confidentiality and integrity, and requires user interaction for successful exploitation. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP Approuter Node.Js Package | 2.6.1 to 16.7.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.