CVE-2025-34156: Tibbo Systems Aggregate Network Manager
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.
Affected products
- Tibbo Systems Aggregate Network Manager: before 6.40.05 (fixed in 6.40.05)
Published 2025-10-23. Last modified 2026-10-08.