Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Funambol has fixed the vulnerability in version v31.0.0.0.
Workaround
No workaround given by the vendor.
References
History
Wed, 28 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs. | |
| Title | Weak encryption on Funambol's cloud server | |
| Weaknesses | CWE-649 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-01-28T10:43:15.171Z
Reserved: 2025-04-16T09:57:03.671Z
Link: CVE-2025-41351
No data.
Status : Received
Published: 2026-01-28T11:15:48.510
Modified: 2026-01-28T11:15:48.510
Link: CVE-2025-41351
No data.
OpenCVE Enrichment
No data.
Weaknesses