CVE-2025-70614
8.1OpenCode Systems · OC Messaging / USSD Gateway
A broken access control flaw in the web-based control panel of OpenCode Systems OC Messaging / USSD Gateway allows authenticated attackers to access arbitrary SMS messages.
Executive summary
A broken access control vulnerability in the OpenCode Systems USSD Gateway allows authenticated low-privileged users to access sensitive SMS message data, posing a significant risk to data confidentiality.
Vulnerability
The application contains a broken access control vulnerability in its web-based control panel. Authenticated attackers with low privileges can exploit this by manipulating a company or tenant identifier parameter to gain unauthorized access to arbitrary SMS messages.
Business impact
Successful exploitation of this vulnerability results in the unauthorized disclosure of sensitive communications, which could lead to severe privacy violations and regulatory non-compliance. Given the CVSS score of 8.1, the high potential for data exfiltration justifies urgent attention to prevent the compromise of critical messaging infrastructure.
Remediation
Immediate Action: Contact OpenCode Systems support to verify if a patch is available for OC Release 6.32.2 and apply it immediately upon receipt.
Proactive Monitoring: Review web server access logs for anomalous requests directed at the control panel, specifically monitoring for unusual values within company or tenant identifier parameters.
Compensating Controls: Implement strict access control lists at the network level to limit administrative panel exposure to trusted management subnets and deploy a Web Application Firewall to filter suspicious parameter input.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the provided GitHub Gist reference.
Analyst recommendation
The severity of this vulnerability, combined with the presence of a public proof-of-concept, necessitates immediate action. Administrators must prioritize restricting access to the affected web-based control panel and coordinate with the vendor to obtain the necessary security updates to remediate the broken access control mechanism.