CVE-2025-45616: Baidu Brcc
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.
Affected products
- Baidu Brcc: up to and including 1.2.0
Published 2025-05-05. Last modified 2026-06-17.