CVE-2025-46408: Avtech Eagleeyes(lite)
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.
Affected products
- Avtech Eagleeyes(lite): version 2.0.0 only
Published 2025-09-15. Last modified 2026-06-17.