CVE-2025-29557 Details
Description
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.
A vulnerability exists in the MailConfiguration API endpoint of ExaGrid EX10 versions 6.3 through 7.0.1.P08. This flaw allows users with operator-level privileges to bypass access controls and retrieve SMTP credentials, including plaintext passwords, through an HTTP request. The vulnerability arises from improper access control, as operator roles should not have access to sensitive credential information.
Users are advised to upgrade to the latest patched version once available, remove unnecessary SMTP configurations, or use tokens where supported. Additionally, monitoring API access logs for MailConfiguration queries from operator accounts is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 31, 2025CISA-ADP
Assessed Jul 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xsu3ks/CVE-2025-29557 | [email protected] | Technical Description |
| https://www.exagrid.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| ExaGrid EX10 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | New CVE Received | [email protected] |
Volerion