216.73.216.6

CVE-2025-41351

· Published 28/01/2026 11:15 · Modified 29/01/2026 16:31

Labels: CVE-2025-41351 2026-01-28CVE-2025-41351CWE-649[email protected]

Essential information

Published
28/01/2026 11:15
Modified
29/01/2026 16:31
Author
Creator
CVSS
6.0 MEDIUM (v3) 6.0 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
funambol / funambol cpe:2.3:a:funambol:funambol:30.0.0.20:*:*:*:*:*:*:*

References