Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
References
| Link | Resource |
|---|---|
| https://gitlab.com/hsleisink/hiawatha/-/blame/master/src/tomahawk.c?ref_type=heads#L429 | Product |
Configurations
History
No history.
Information
Published : 2026-01-26 18:16
Updated : 2026-06-17 09:43
NVD link : CVE-2025-57784
Mitre link : CVE-2025-57784
CVE.ORG link : CVE-2025-57784
JSON object : View
Products Affected
hiawatha-webserver
- hiawatha
CWE
