CVE-2025-5087: Kaleris Navis n4

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capable of observing network traffic between Ultra Light Clients and N4 servers can extract sensitive information, including plaintext credentials.

Affected products

  • Kaleris Navis n4: before 4.0 (fixed in 4.0)

Published 2025-06-24. Last modified 2026-06-17.