Junglewise Threat Intelligence

CVE-2025-13477: Digital Operations WifiBurada authentication bypass via unprotected credentials

CVE-2025-13477 · Severity: high · CVSS 7.1 · Published 2026-05-21

Executive brief

WifiBurada, a digital operations service, contains a security flaw that fails to properly protect user credentials and private information. An attacker could exploit this to bypass authentication mechanisms and gain unauthorized access to the system. This could lead to the exposure of sensitive customer data and unauthorized use of the service.

Technical details

WifiBurada is vulnerable to an authentication bypass stemming from insufficiently protected credentials (CWE-522) and the exposure of private personal information to unauthorized actors (CWE-359). The vulnerability allows a network-based attacker with low privileges to bypass security controls and access sensitive data. According to the advisory, the vendor was notified but did not respond, and no official patch has been confirmed. The CVSS 3.1 score of 7.1 reflects high confidentiality impact but limited integrity and availability impact.

Affected products

  • Digital Operations Services Inc. WifiBurada through 21052026

Timeline

  • 2026-05-21: advisory: NVD and TR-CERT published the vulnerability details.
  • 2026-05-21: disclosed: Public disclosure occurred after the vendor failed to respond to early contact.

References