VDB

CVE-2025-57784

CVE-2025-57784 PUBLISHED CVSS 3.299999952316284 LOW

Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.

EPSS 0.02% · 3.3th percentile

Risk Scores

CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.02%
3.3th percentile

Affected Products

VendorProductVersions
hiawatha-webserverhiawatha11.7
HiawathaHiawatha Web server11.7

Timeline

  • Sep 9, 2025 PoC Published
  • Jan 26, 2026 CVE Published
  • Jan 26, 2026 CVE Updated
  • Jan 27, 2026 EPSS Score
  • Jan 30, 2026 EPSS Score
  • Feb 1, 2026 EPSS Score
  • Feb 4, 2026 EPSS Score
  • Feb 6, 2026 EPSS Score
  • Feb 9, 2026 EPSS Score
  • Feb 11, 2026 EPSS Score
  • Feb 14, 2026 EPSS Score
  • Feb 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›