CVE-2025-25535 is a critical HTTP Response Manipulation vulnerability in SCRIPT CASE v.1.0.002 Build7, allowing remote attackers to achieve privilege escalation through crafted requests. With a CVSS score of 9.8 (CRITICAL), it presents a low-complexity attack vector with high impact on confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion, indicating awareness. The EPSS and FAUCET Risk Score suggest a moderate to high likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.