← Back to CVE List
CVE-2025-57784NVD
Vulnerability Summary
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
CVSS v3.1 Base Metrics — Score 3.3 (LOW)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Hiawatha-webserver Hiawatha
Not provided by NVD for this CVE.