CVE-2025-57784
EUVD-2025-20634226.01.2026, 18:16
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hiawatha-webserver | hiawatha | 11.7 |
𝑥
= Vulnerable software versions