CVE-2025-25749 Details
Description
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
A vulnerability exists in HotelDruid versions through 3.0.7, allowing users to create weak passwords due to the absence of password strength requirements. This flaw can lead to easily guessable passwords, increased risk of credential reuse, and a higher likelihood of account compromise, particularly for administrative users.
Users are advised to implement stronger password policies, including complexity requirements, password history restrictions, and minimum password age enforcement. Providing real-time feedback on password strength and auditing administrative credentials for strength during installation are also recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.huyvo.net/post/cve-2025-25749-weak-password-policy-in-hoteldruid-3-0-7 | [email protected] | ExploitMitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-521 | Weak Password Requirements | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| digitaldruid hoteldruid | <= 3.0.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2025 | Initial Analysis | [email protected] |
| Mar 24, 2025 | CVE Modified | CISA-ADP |
| Mar 11, 2025 | New CVE Received | [email protected] |