CVE-2025-55129: Medium severity Revive Adserver vulnerability
HackerOne community member Kassem S.(kassems94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation has been independently reported by other HackerOne users, such as itzhari and khoof.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55129?
CVE-2025-55129 is considered a high severity vulnerability due to its potential for username impersonation attacks.
How do I fix CVE-2025-55129?
To fix CVE-2025-55129, update to the latest version of Revive Adserver that includes the patched username handling mechanism.
What types of attacks are associated with CVE-2025-55129?
CVE-2025-55129 is associated with impersonation attacks that utilize homoglyph techniques to mislead users.
Is CVE-2025-55129 a regression of a previous vulnerability?
Yes, CVE-2025-55129 represents a regression in the username handling fix intended to address vulnerabilities like CVE-2025-52672.
Who reported CVE-2025-55129?
CVE-2025-55129 was reported by Kassem S., a member of the HackerOne community.