CVE-2025-4378

CRITICAL

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass.This...

Affects 0 products across 2 vendors.

BCS6.65
CVSS 3.110.0
EPSS0.3%
Percentile21th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact.
CWE Weakness Definitions
CWE-319: CWE-319
CWE-798: Use of Hard-Coded Credentials

Software contains embedded passwords or keys that cannot be changed by the administrator.

Related Attack Patterns (CAPEC)
CAPEC-65 Sniff Application Code
via CWE-319
CAPEC-70 Try Common or Default Usernames and Passwords
via CWE-798
CAPEC-102 Session Sidejacking
via CWE-319
CAPEC-191 Read Sensitive Constants Within an Executable
via CWE-798
CAPEC-383 Harvesting Information via API Event Monitoring
via CWE-319
Show all 7

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The Ataturk University ATA-AOF Mobile Application before version 20.06.2025 is vulnerable to cleartext transmission of sensitive information and the use of hard-coded credentials, which could lead to authentication abuse and bypass.

BSID: BS-2025-GLOBAL-038565-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-4378?
The Ataturk University ATA-AOF Mobile Application before version 20.06.2025 is vulnerable to cleartext transmission of sensitive information and the use of hard-coded credentials, which could lead to authentication abuse and bypass.
What is the CVSS score for CVE-2025-4378?
CVE-2025-4378 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L. EPSS: 0.3%.
Is CVE-2025-4378 actively exploited?
No confirmed active exploitation of CVE-2025-4378 as of 2026-05-30.
How do I remediate CVE-2025-4378?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-4378?
CVE-2025-4378 affects: Abuse, Mobile.
Vulnerability Details
CVE IDCVE-2025-4378
BSIDBS-2025-GLOBAL-038565-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Published2025-06-24
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass.This issue affects ATA-AOF Mobile Application: before 20.06.2025.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can intercept the network traffic to obtain sensitive information transmitted in cleartext. Additionally, the presence of hard-coded credentials in the application can be exploited to gain unauthorized access without proper authentication.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Abuse —
Mobile —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 407 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashf38ba0a00809041c766a3a926b4c825dde883478d009a6598363535069377a9798e1411234191bf8a653efd98eae8614ce884da18b15c3e69dbc9e20316d9e3d
Related CVEs affecting Abuse
CVE-2024-28189 10.0 Judge0 is an open-source online code execution system. The application uses t... CVE-1999-0512 10.0 A mail server is explicitly configured to allow SMTP mail relay, which allows... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th... CVE-2026-27389 9.8 Authentication Bypass Using an Alternate Path or Channel vulnerability in des...
View all Abuse CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →