CVE-2025-5781
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before 11.0.5-00; Hitachi Device Manager: from 8.4.1-00 before 8.6.5-00.
- Affected products
- Hitachi Configuration Manager, Hitachi Device Manager, Hitachi Ops Center Api Configuration Manager
- Hitachi Configuration Manager
- All versions
- Hitachi Device Manager
- < 8.6.5-00
- Hitachi Ops Center Api Configuration Manager
- < 11.0.5-00
- CVSS 3.1
- 5.2 MEDIUM
- EPSS
- 0.1% (1th percentile)
- Weakness
- CWE-532
- NVD status
- Analyzed
- Published
- 2026-02-25
- Attack patterns
- CAPEC-593
- Entry point
- payload query param
- Path
- admin/ajax.php
CVE-2025-5781 at NVD
2 known exploits for CVE-2025-5781
Proof-of-concept code and exploit modules indexed by Sploitus