CVE-2025-34156: Tibbo Systems Aggregate Network Manager

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.

Affected products

  • Tibbo Systems Aggregate Network Manager: before 6.40.05 (fixed in 6.40.05)

Published 2025-10-23. Last modified 2026-10-08.