CVE-2025-70614Disclosure(opencode / ussd_gateway)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged attackers to gain to access to arbitrary SMS messages via a crafted company or tenant identifier parameter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ussd_gateway

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-08); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
ussd_gateway

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-08: 3Mentions · 2026-03-26: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 303-0503-0803-26
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-083
Disclosure3
2026-03-261
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-70614 OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated lo… https://www.cve.org/CVERecord?id=CVE-2025-70614

    Post summary

    The CVE-2025-70614 report notes a broken access control flaw in OpenCode Systems OC Messaging/USSD Gateway’s web control panel, without evidence of active exploitation, exploit availability, or patch details.

    00010614
    56.6K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🚨 Another day, another “whoops” in access control: tenant-boundary SMS leaks. CVE-2025-70614 (8.1) means your messages may not be as secure as the UI claims. Fix fast. https://windowsforum.com/threads/cve-2025-70614-fix-tenant-sms-access-control-flaw-in-oc-messaging-ussd-gateway.407633/ #TelecomSecurity #TenantAccessControl #Cve202570614 #SmsMessagingGateway https://t.co/eQlYcn564i

    Post summary

    The tweet announces that CVE-2025-70614, rated 8.1, causes tenant-boundary SMS leaks, urging users to patch as soon as possible.

    00000176
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-70614 OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated lo… https://www.cve.org/CVERecord?id=CVE-2025-70614 ----- Traducción: CVE-2025-70614 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑70614, a broken access control flaw in the web‑based control panel of OpenCode Systems’ OC Messaging/USSD Gateway (Release 6.32.2), with a link to the official CVE record.

    0000090
    56 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-70614 - High OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged attackers to... https://www.thehackerwire.com/vulnerability/CVE-2025-70614/ https://t.co/MPAaGrOLFY

    Post summary

    OpenCode Systems Release 6.32.2 is disclosed to have a broken access control vulnerability in its web-based control panel, enabling authenticated low‑privileged attackers.

    00000119
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-70614 Access Control Bypass in OpenCode Systems OC Messaging Gateway 6.32.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70614

    Post summary

    The post merely announces CVE‑2025‑70614 as an access control bypass in OC Messaging Gateway 6.32.2, without providing proof‑of‑concepts, exploit details, or mitigation information.

    00000106
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopencodeussd_gateway6.32.2--

Explore more