CVE-2025-70614: High severity OpenCode Systems OC Messaging / USSD Gateway vulnerability
OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged attackers to gain to access to arbitrary SMS messages via a crafted company or tenant identifier parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70614?
CVE-2025-70614 is classified as a critical vulnerability due to its potential impact on sensitive SMS messages.
How do I fix CVE-2025-70614?
To mitigate CVE-2025-70614, apply the latest security updates from OpenCode Systems for OC Messaging / USSD Gateway version 6.32.2.
Who is affected by CVE-2025-70614?
Users of OpenCode Systems OC Messaging / USSD Gateway version 6.32.2 are affected by CVE-2025-70614.
What type of attacks can CVE-2025-70614 enable?
CVE-2025-70614 allows authenticated low-privileged attackers to read arbitrary SMS messages through broken access controls.
What is the impact of exploiting CVE-2025-70614?
Exploiting CVE-2025-70614 can lead to unauthorized access to confidential SMS communications, compromising user privacy.