CVE-2025-69246Disclosure(raytha / raytha)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch raytha raytha systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.6.

0.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • raytha

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
raytha

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-16: 4Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-16: 303-16
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, profissionais de segurança! A falha no Raytha CMS permite ataques de força bruta sem proteção no login. Atualize para a v1.4.6 e implemente MFA para proteger suas contas! Não espere até ser tarde demais! 🔒 🔗 https://www.tenable.com/cve/CVE-2025-69246 #CyberSecurity #InfoSec #MFA

    Post summary

    The tweet alerts users that CVE‑2025‑69246 in Raytha CMS allows brute‑force login attacks and urges them to patch to v1.4.6 and enable MFA for protection.

    00000125
    257 followersView on X
  • Fernando Karl@fernandokarl
    General

    🔒 New vulnerability alert: CVE-2025-69246 is making waves in the cybersecurity realm! It's crucial to assess your systems and patch vulnerabilities ASAP. Don’t let outdated software be your downfall! Stay informed, stay protected. 💻🔍 #Cybersecurity #VulnerabilityManagement

    Post summary

    The post alerts about CVE‑2025‑69246 but gives no further technical details, exploitation information, or specific patch guidance.

    00000101
    257 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69246 Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout,… https://www.cve.org/CVERecord?id=CVE-2025-69246

    Post summary

    The post discloses that Raytha CMS lacks brute force protection, enabling repeated automated login attempts without triggering a lockout.

    00000140
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-69246 - Lack of bruteforce protection in Raytha CMS Intel Report: https://ift.tt/ezJkZnb

    Post summary

    A brief alert announces CVE‑2025‑69246, noting a missing brute‑force protection in Raytha CMS and links to an intel report.

    0000073
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appraytharaytha---

Explore more