Medium severityNVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
CVE-2026-34025
CVE-2026-34025
Description
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from the HTTP X-Forwarded-For header when that header is present. An attacker with valid branch user credentials can manipulate the X-Forwarded-For header during login to spoof the expected branch IP address and obtain a valid authenticated session from an unauthorized network location.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: = 6.15.8328.28014
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.