CVE-2025-30035Disclosure

LOWCVSS 9.0 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and grants access to the system with the privileges of the targeted user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-02: 3Technical Details · 2026-03-02: 303-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-30035 Authentication Bypass in CGM CLININET Enabling Unauthorized User Session Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-30035

    Post summary

    The text announces CVE-2025-30035, an authentication bypass vulnerability in CGM CLININET that permits unauthorized session takeover, with no PoC, exploit, patch, or active exploitation details provided.

    0000081
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-30035 The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, withou… https://www.cve.org/CVERecord?id=CVE-2025-30035 ----- Traducción: La vulnerabilidad … http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-30035, describing an authentication bypass in CGM CLININET that lets attackers access any active user account using only a username, with no mention of PoC, exploit code, or patches.

    0000095
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-30035 The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, withou… https://www.cve.org/CVERecord?id=CVE-2025-30035

    Post summary

    CVE-2025-30035 enables attackers to bypass authentication in CGM CLININET by providing only a username, granting access to any active user account.

    00000403
    56.6K followersView on X

Explore more