CVE-2025-65239: Medium severity OpenCode Systems USSD Gateway OC Release vulnerability
Published Nov 26, 2025
·Updated
Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.
Affected Software
2 affected components
OpenCode Systems USSD Gateway OC Release
OpenCode USSD Gateway=6.13.11
Event History
Nov 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65239?
CVE-2025-65239 has a medium severity rating due to its potential to expose sensitive server logs.
2
How do I fix CVE-2025-65239?
To fix CVE-2025-65239, implement proper access controls to restrict access to the /aux1/ocussd/trace endpoint.
3
Who is affected by CVE-2025-65239?
CVE-2025-65239 affects users of OpenCode Systems USSD Gateway OC Release version 6.13.11.
4
What exploit methods are associated with CVE-2025-65239?
Exploitation of CVE-2025-65239 can occur through users with low-level privileges accessing restricted server logs.
5
What are the consequences of CVE-2025-65239?
The consequences of CVE-2025-65239 include unauthorized access to sensitive log information, potentially leading to further attacks.