Security Advisory

CVE-2025-41351

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-28 10:43:15
Last updated 2026-01-28 16:33:24
Assigner INCIBE
State PUBLISHED

Description

Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.