CVE-2025-41257
Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-03-04 23:16:09
Güncelleme
2026-03-09 21:16:10
Source Identifier
1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251104-02_Suprema_BioStar_2_Insecure_Password_Change
https://www.supremainc.com/en/platform/hybrid-security-platform-biostar-2.asp
https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251104-02_Suprema_BioStar_2_Insecure_Password_Change