Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 26 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client. | |
| Title | Tomahawk authentication timing attack due to usage of 'strcmp' | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-01-26T20:52:06.748Z
Reserved: 2025-08-19T17:36:13.586Z
Link: CVE-2025-57784
Updated: 2026-01-26T20:51:54.545Z
Status : Received
Published: 2026-01-26T18:16:27.467
Modified: 2026-01-26T21:15:55.297
Link: CVE-2025-57784
No data.
OpenCVE Enrichment
No data.