CVE-2025-34081: CONPROSYS HMI System (CHS) < 3.7.7 Exposed PHP Debug Info
Published Jul 1, 2025
·Updated
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacker.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
Affected Software
2 affected components
Contec CONPROSYS HMI System (CHS)<3.7.7
Contec CONPROSYS HMI System<3.7.7
Event History
Jul 1, 2025
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 14, 57682
Event
via NVD·03:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-34081?
CVE-2025-34081 is considered a critical vulnerability due to the potential exposure of sensitive data to unauthenticated users.
2
How do I fix CVE-2025-34081?
To fix CVE-2025-34081, upgrade to version 3.7.7 or later of the Contec COs. PROSYS HMI System (CHS).
3
What type of data can be exposed by CVE-2025-34081?
CVE-2025-34081 can expose sensitive configuration and environment data via a PHP phpinfo() debug page.
4
Which versions of Contec CONPROSYS HMI System (CHS) are affected by CVE-2025-34081?
CVE-2025-34081 affects all versions of Contec CONPROSYS HMI System (CHS) prior to 3.7.7.
5
Is authentication required to access the vulnerable page in CVE-2025-34081?
No, the vulnerable PHP phpinfo() debug page is accessible to unauthenticated users.