CVE-2025-65951 affects the Inside Track / Entropy Derby horse-racing betting engine, specifically its VDF-based timelock encryption system. The vulnerability, patched in commit 2d38d2f, allowed the betting operator to bypass the intended sequential delay by immediately decrypting bet tickets. This is rated as a High severity vulnerability (CVSS 8.7) due to its network-based attack vector, low attack complexity, and high impact on confidentiality and integrity, allowing the operator to gain an unfair advantage. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mescuwa | Entropy-Derby | < 2d38d2f16bbb3b4240698148f80d8c5202725c77CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.