Home

Description

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.

PUBLISHED Reserved 2025-11-07 | Published 2025-11-12 | Updated 2025-11-12 | Assigner twcert




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-1390 Weak Authentication

Product status

Default status
unaffected

Any version
affected

References

www.chtsecurity.com/.../b97e8337-6b0c-43e8-8e8c-187b7c0e13c2

www.twcert.org.tw/tw/cp-132-10486-a3459-1.html third-party-advisory

www.twcert.org.tw/en/cp-139-10487-12a32-2.html third-party-advisory

cve.org (CVE-2025-12870)

nvd.nist.gov (CVE-2025-12870)

Download JSON