CVE-2025-50110: High severity AVTECH EagleEyes Lite vulnerability
An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50110?
CVE-2025-50110 is classified as a high-severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2025-50110?
To fix CVE-2025-50110, ensure that sensitive information is not transmitted as plaintext query parameters and implement secure coding practices.
What type of information is exposed by CVE-2025-50110?
CVE-2025-50110 exposes sensitive information including internal server URLs, account IDs, passwords, and device tokens.
Which software is affected by CVE-2025-50110?
CVE-2025-50110 affects AVTECH EagleEyes Lite version 2.0.0.
What method in AVTECH EagleEyes Lite is vulnerable in CVE-2025-50110?
The vulnerable method in AVTECH EagleEyes Lite is push.lite.avtech.com.AvtechLib.GetHttpsResponse.