A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions = V7.80 = V7.80 = V7.80), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 = V7.80 = V7.80), SIPROTEC 5 7SA82 (CP150) (All versions = V7.80 = V7.80 = V7.80), SIPROTEC 5 7SD82 (CP150) (All versions = V7.80 = V7.80 = V7.80), SIPROTEC 5 7SJ81 (CP150) (All versions = V7.80), SIPROTEC 5 7SJ82 (CP150) (All versions = V7.80 = V7.80 = V7.80), SIPROTEC 5 7SK82 (CP150) (All versions = V7.80 = V7.80), SIPROTEC 5 7SL82 (CP150) (All versions = V7.80 = V7.80 = V7.80 < V9.80), SIPROTEC 5 7ST85 (CP300) (All versions), SIPROTEC 5 7ST86 (CP300) (All versions < V9.80), SIPROTEC 5 7SX82 (CP150) (All versions < V9.80), SIPROTEC 5 7SX85 (CP300) (All versions < V9.80), SIPROTEC 5 7SY82 (CP150) (All versions = V7.80 = V7.80), SIPROTEC 5 7UT82 (CP150) (All versions = V7.80 = V7.80 = V7.80 = V7.80 = V7.80 < V9.80), SIPROTEC 5 7VU85 (CP300) (All versions < V9.80), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.80). Affected devices do not properly limit the path accessible via their webserver. This could allow an authenticated remote attacker to read arbitrary files from the filesystem of affected devices.
CVE-2025-10304 – Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 – Missing Authorization to Unauthenticated Backup Failure
CVE ID : CVE-2025-10304 Published : Dec. 3, 2025, 3:27 a.m. | 26 minutes ago Description : The Everest Backup –