Home

Description

On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights.

PUBLISHED Reserved 2025-10-30 | Published 2025-10-31 | Updated 2025-10-31 | Assigner bizerba




HIGH: 8.4CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-829 Inclusion of Functionality from Untrusted Control Sphere

Product status

Default status
affected

0.0 (semver) before 3.07
affected

Timeline

2025-10-30:Release of new version BRAIN2 3.07
2025-10-30:Publish Security Advisory

References

www.bizerba.com/...on-security/2025/bizerba-sa-2025-0007.pdf

cve.org (CVE-2025-12509)

nvd.nist.gov (CVE-2025-12509)

Download JSON