CVE-2025-55129: Medium severity Revive Adserver vulnerability

Published Dec 2, 2025
·
Updated

HackerOne community member Kassem S.(kassems94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation has been independently reported by other HackerOne users, such as itzhari and khoof.

Affected Software

2 affected components
Revive Adserver
Aquaplatform Revive Adserver>=6.0.0<6.0.4

Event History

Dec 2, 2025
CVE Published
via MITRE·01:42 AM
Data Sourced
via MITRE·01:42 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-55129?

CVE-2025-55129 is considered a high severity vulnerability due to its potential for username impersonation attacks.

2

How do I fix CVE-2025-55129?

To fix CVE-2025-55129, update to the latest version of Revive Adserver that includes the patched username handling mechanism.

3

What types of attacks are associated with CVE-2025-55129?

CVE-2025-55129 is associated with impersonation attacks that utilize homoglyph techniques to mislead users.

4

Is CVE-2025-55129 a regression of a previous vulnerability?

Yes, CVE-2025-55129 represents a regression in the username handling fix intended to address vulnerabilities like CVE-2025-52672.

5

Who reported CVE-2025-55129?

CVE-2025-55129 was reported by Kassem S., a member of the HackerOne community.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203