What is CVE-2025-27621?
CVE-2025-27621 is a vulnerability in UpTrain platform (version 0.7.1 and prior) where a default user with a static username serves as the default API key. Combined with an open CORS policy, this allows unauthorized remote access using the predictable key. Updating to the latest version is recommended.
Azərbaycanca: CVE-2025-27621, UpTrain platformunda (0.7.1 və əvvəlki versiyalar) statik istifadəçi adı ilə yaradılan default API açarı zəifliyidir. Açıq CORS siyasəti ilə birlikdə, uzaqdan hücumçu bu standart açarı istifadə edərək sistemə yetkisiz giriş əldə edə bilər. UpTrain-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Which platform and versions are affected by CVE-2025-27621?
The vulnerability affects the UpTrain platform version 0.7.1 and prior.
How is unauthorized remote access possible using CVE-2025-27621?
Due to the default API key created with a static username, combined with the open CORS policy, a remote attacker can gain unauthorized access using this predictable key.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.