An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. This is a server-side authorization fix.
History

Tue, 04 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Cfmoto
Cfmoto ride
Vendors & Products Cfmoto
Cfmoto ride

Tue, 04 Nov 2025 10:30:00 +0000

Type Values Removed Values Added
Description An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. This is a server-side authorization fix.
Title IDOR vulnerability in the CFMOTO RIDE API
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N/E:F/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-NL

Published: 2025-11-04T10:25:45.416Z

Updated: 2025-11-04T20:20:24.720Z

Reserved: 2025-10-13T14:34:20.917Z

Link: CVE-2025-11690

cve-icon Vulnrichment

Updated: 2025-11-04T20:20:03.747Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-04T11:15:37.573

Modified: 2025-11-04T15:40:45.533

Link: CVE-2025-11690

cve-icon Redhat

No data.