First published: Wed Apr 23 2025(Updated: )
This vulnerability exists in KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this vulnerability by intercepting the request and removing the Captcha parameter leading to bypassing the Captcha verification mechanism.
Credit: vdisclose@cert-in.org.in
Affected Software | Affected Version | How to fix |
---|---|---|
Meon KYC solutions |
Upgrade KYC Solutions to version 1.2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-42601 is considered a critical vulnerability due to the potential for remote exploitation.
To fix CVE-2025-42601, ensure proper server-side validation of Captcha in all API endpoints.
CVE-2025-42601 can allow attackers to bypass Captcha verification, potentially leading to unauthorized access.
CVE-2025-42601 affects Meon KYC solutions that implement vulnerable API endpoints.
Yes, CVE-2025-42601 can be exploited remotely by intercepting and modifying API requests.