CVE-2025-14197 Details
Description
A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/resources/f96956469e7be39d of the component Web Administration Module. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing unauthorized access to sensitive information has been identified in Verysync 微力同步 versions through 2.21.3. The issue resides in the Web Administration Module, specifically within an unprotected function of the file '/rest/f/api/resources/f96956469e7be39d'. This vulnerability arises because the module's core interface lacks proper authentication, enabling remote attackers to access and retrieve confidential data such as device IDs, system configurations, and synchronization files, potentially leading to further targeted attacks.
Users are advised to implement authentication for the Web Administration Module and to restrict access to local or whitelisted devices. Additionally, enabling log auditing to monitor access records and file reading operations can help detect and respond to abnormal activities.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 7, 2025CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/jjjjj-zr/jjjjjzr/issues/6 | [email protected] | ExploitIssue TrackingRemedyTechnical Description |
| https://github.com/jjjjj-zr/jjjjjzr/issues/8 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/?ctiid.334617 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.334617 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.699498 | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?submit.699537 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Beijing Weili Digital Technology Co., Ltd 微力同步 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 7, 2025 | New CVE Received | [email protected] |
Volerion