Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.
History

Mon, 26 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.
Title Improper Neutralization in Altitude Communication Server
Weaknesses CWE-74
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-01-26T13:49:41.248Z

Reserved: 2025-04-16T09:09:35.597Z

Link: CVE-2025-41083

cve-icon Vulnrichment

Updated: 2026-01-26T13:49:37.358Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-26T10:16:06.100

Modified: 2026-01-26T15:03:33.357

Link: CVE-2025-41083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.