Vulnerability Description
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ncp-E | Ncp Secure Entry Client | 13.19 |
| Ncp-E | Secure Enterprise Client | 13.18 |
Related Weaknesses (CWE)
References
- https://pentest.axians.de/viewer.html?file=cve-2025-26155/CVE-axians-eng.pdfExploitThird Party Advisory
- https://www.ncp-e.com/Product
FAQ
What is CVE-2025-26155?
CVE-2025-26155 is a vulnerability with a CVSS score of 9.8 (CRITICAL). NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
How severe is CVE-2025-26155?
CVE-2025-26155 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-26155?
Check the references section above for vendor advisories and patch information. Affected products include: Ncp-E Ncp Secure Entry Client, Ncp-E Secure Enterprise Client.