CVE-2025-10695Disclosure(opensupports / opensupports)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction. This issue affects OpenSupports: 4.11.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opensupports

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
opensupports

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-27: 101-27
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • Fluid Attacks@fluidattacks
    Disclosure

    Fluid Attacks' research team found a zero-day vulnerability in OpenSupports. As a #CNA, we assigned the ID CVE-2025-10695. Details here: 🔗 https://fluidattacks.com/advisories/freer. We have disclosed 217 #CVE to this date: 🔗https://fluidattacks.com/advisories/. https://t.co/si3YfUZPH6

    Post summary

    Fluid Attacks announces a zero‑day CVE‑2025‑10695 in OpenSupports and links to an advisory, but provides no exploit or patch information.

    0000054
    872 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensupportsopensupports4.11.0--

Explore more