CVE-2025-34156EPSS p29.1%
CVE-2025-34156CVE-2025-34156
Description
Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.
Scoring
| EPSS | 0.37% probability of exploitation · percentile 29.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |