Executive brief
Vedo Suite 2024.17 contains a security flaw that allows unauthorized individuals to gain high-level access to the system. By sending a specifically crafted web request, an attacker can obtain a valid security token without needing a username or password. This could lead to unauthorized access to sensitive data or administrative functions within the suite.
Technical details
An improper access control vulnerability exists in Vedo Suite 2024.17 within the /autologin/ API endpoint. The application fails to properly validate requests to this endpoint, allowing a remote, unauthenticated attacker to obtain a high-privilege JSON Web Token (JWT) by simply sending an empty HTTP POST request. With this token, the attacker can bypass authentication mechanisms and perform actions with elevated privileges. The vulnerability is tracked as CVE-2025-51054 and has a CVSS score of 6.5.
Affected products
- Vedo Suite Project Vedo Suite 2024.17
Timeline
- 2025-08-06: disclosed: Initial NVD publication date