Back to search
CVE-2025-41083
Published: Jan 26, 2026
Modified: Jan 26, 2026
PUBLISHED
Description
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.
| Vendor | Product | Versions |
|---|---|---|
Altitude | Altitude Communication Server | affected 8.5.3290.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now