CVE-2025-52666
Estado: AnalizadaBaja (2.7)—
Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 2.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.42%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-134
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-52666",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-52666",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-11-20T21:42:31.010532Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 2.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "Revive",
"product": "Revive Adserver",
"versions": [
{
"status": "affected",
"version": "6.0.1",
"versionType": "semver",
"lessThanOrEqual": "6.0.1"
},
{
"status": "affected",
"version": "5.5.2",
"versionType": "semver",
"lessThanOrEqual": "5.5.2"
},
{
"status": "unaffected",
"version": "6.0.2",
"versionType": "semver",
"lessThanOrEqual": "6.0.2"
},
{
"status": "unaffected",
"version": "5.5.3",
"versionType": "semver",
"lessThanOrEqual": "5.5.3"
}
]
}
]
}
],
"published": "2025-11-20T20:16:22.687",
"references": [
{
"url": "https://hackerone.com/reports/3399218",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://hackerone.com/reports/3399218",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-134"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error."
},
{
"lang": "es",
"value": "Neutralización incorrecta de caracteres de formato en la configuración de Revive Adserver 5.5.2 y 6.0.1 y versiones anteriores provoca que un usuario administrador deshabilite la consola de usuario administrador debido a un error fatal de PHP."
}
],
"lastModified": "2026-09-26T00:10:00.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47AC2D81-BA0C-404A-B6F6-31151956D422",
"versionEndIncluding": "5.5.2"
},
{
"criteria": "cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42E4B7BD-5F7B-4FBE-93D2-C19F30FA5A51",
"versionEndIncluding": "6.0.1",
"versionStartIncluding": "6.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}