← Back to browse · API

CVE-2025-34143

Severity
CRITICAL
CVSS
9.3
EPSS
0.29857
Risk score
47.65
CISA KEV
No
PoC
No
Published
2025-07-22
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2025-22321, GHSA-V93R-Q3GH-68X8
Products
ETQ:Reliance CG (legacy) 0 <MP-4583
Sources
euvd EUVD-2025-22321

Description

An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field. The SYSTEM account does not require a password, enabling attackers with network access to the login page to obtain elevated access. Once authenticated, an attacker could achieve remote code execution by modifying Jython scripts within the application. This issue was resolved by introducing stricter validation logic to exclude internal accounts from public authentication workflows in version MP-4583.

References