← Vulnerability feed

Vulnerability record · CVE-2025-49181 · published 12 June 2025

CVE-2025-49181: Sick media server missing authorization vulnerability

Sick · Media Server

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack.

8.6 CVSS 3.1 High EPSS 0.40% · top 68.0% CWE-862 · Missing authorization
8.6CVSS 3.1 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49181 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-49195Sick media server improper restriction of authentication attempts vulnerabilityThe FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compro…EPSS 0.52%9.8CVE-2025-49182Sick media server vulnerabilityFiles in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full acces…EPSS 0.55%7.5CVE-2025-49198Sick media server vulnerabilityThe Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing …EPSS 0.38%7.5CVE-2025-49194Sick media server cleartext transmission vulnerabilityThe server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept tra…EPSS 0.32%7.5CVE-2025-49197Sick media server vulnerabilityThe application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.EPSS 0.30%7.5CVE-2025-49183Sick media server cleartext transmission vulnerabilityAll communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads t…EPSS 0.31%6.1CVE-2025-49192Sick field analytics clickjacking vulnerabilityThe web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into cli…EPSS 0.33%6.1CVE-2025-49193Sick baggage analytics vulnerabilityThe application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., p…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2025-49181), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.