Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-26 18:16
Updated : 2026-01-27 14:59
NVD link : CVE-2025-57784
Mitre link : CVE-2025-57784
CVE.ORG link : CVE-2025-57784
JSON object : View
Products Affected
No product.
CWE
No CWE.
