Junglewise Threat Intelligence

CVE-2025-7743: Dolusoft Omaspot cleartext transmission of sensitive information

CVE-2025-7743 · Severity: critical · CVSS 9.6 · Published 2025-09-16

Technologies: Dolusoft Omaspot. Vendors: Dolusoft.

Executive brief

A vulnerability in Dolusoft Omaspot allows sensitive information to be transmitted over the network without encryption. This could allow an attacker on the same local network to intercept login credentials or other private data, potentially leading to full account takeover and unauthorized access to the system. The issue impacts versions of the service released before September 12, 2025.

Technical details

Dolusoft Omaspot is vulnerable to CWE-319 (Cleartext Transmission of Sensitive Information). The application transmits sensitive data over unencrypted channels, which can be intercepted by an attacker with adjacent network access (e.g., on the same local network or Wi-Fi). This lack of encryption allows for the interception of credentials or session tokens, facilitating privilege escalation and unauthorized administrative access. The vulnerability is addressed in updates released on or after September 12, 2025.

Affected products

  • Dolusoft Omaspot before 12.09.2025

Timeline

  • 2025-09-16: advisory: Initial publication of CVE-2025-7743
  • 2025-09-12: patched: Fix released in version 12.09.2025

References

Related threats