CVE-2025-42605: Improper Access Control Vulnerability in Meon Bidding Solutions

9.3 CVSS

Description

This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body to gain unauthorized access to other user accounts.

Successful exploitation of this vulnerability could allow remote attacker to perform authorized manipulation of data associated with other user accounts.

Classification

CVE ID: CVE-2025-42605

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.3

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N

Problem Types

CWE-639: Authorization Bypass Through User-Controlled Key

Affected Products

Vendor: Meon

Product: Bidding Solutions

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.22% (probability of being exploited)

EPSS Percentile: 45.35% (scored less or equal to compared to others)

EPSS Date: 2025-05-22 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-42605
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0082

Timeline