CVE-2025-55128 Details
Description
HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service.
A resource exhaustion vulnerability has been identified in Revive Adserver within the user log viewer interface. This issue allows an authenticated user with admin access to request excessively large data sets by manipulating the 'setPerPage' parameter. The server's response to these large requests can lead to significant memory and CPU usage, increased database I/O, and potential application timeouts or crashes, causing a denial-of-service condition. Additionally, if the application returns all data in a single response, it can overwhelm the client's browser, causing it to hang.
A patch is available and can be applied to address this vulnerability. Instructions for applying the patch can be found on the Revive Adserver security update page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hackerone.com/reports/3413890 | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| aquaplatform revive adserver | >= 6.0.0, < 6.0.3 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Dec 2, 2025 | CVE Modified | [email protected] |
| Dec 1, 2025 | CVE Modified | CISA-ADP |
| Nov 20, 2025 | New CVE Received | [email protected] |