AZGingerHacker[verified]@AZGingerHackerDisclosure
A brief tweet announcing CVE-2025-12543 (Host Header Validation Bypass in Undertow) with a link to further details, highlighting the risk of trusting attacker-controlled HTTP headers, but lacking exploit, PoC, or patch information.
ThreatSynop[verified]@ThreatSynopDisclosure
HPE disclosed CVE-2025-12543, a critical Host header validation flaw in Telco Service Activator with CVSS 9.6, and urges users to upgrade to version 10.5.0 to mitigate the remote access bypass.
mysocAi[verified]@MysocAiPatch
HPE has disclosed a critical remote access control bypass flaw (CVE-2025-12543) and urges users to apply updates to mitigate the risk.
ThreatSynop[verified]@ThreatSynopPatch
HPE disclosed a critical Host‑header validation flaw (CVE‑2025‑12543) that allows attackers to bypass access controls; a patch is available via TSA 10.5.0+ and exposure should be restricted.
Komodo Cyber Security[verified]@KomodosecGeneral
The tweet announces a new CVE (CVE‑2025‑12543) regarding a critical flaw in Undertow, but offers no further technical details, PoC, exploit, or mitigation information.
iototsecnews@iototsecnewsDisclosure
CVE‑2025‑12543 is a severe vulnerability in HPE Telco Service Activator caused by improper validation of the Host header in the Undertow HTTP server, enabling unauthenticated attackers to bypass access controls; the text provides technical details but no proof‑of‑concept, exploit, or report of active exploitation.
CERT-PY@CERTpyGeneral
The tweet announces CVE-2025-12543 affecting HPE products and directs readers to a link for more information, but offers no further technical or exploit details.