Home

Description

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information.This issue affects Brokerage Automation: before 1.1.71.

PUBLISHED Reserved 2025-08-11 | Published 2025-11-14 | Updated 2025-11-14 | Assigner TR-CERT




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

CWE-640 Weak Password Recovery Mechanism for Forgotten Password

CWE-302 Authentication Bypass by Assumed-Immutable Data

Product status

Default status
unaffected

Any version before 1.1.71
affected

Credits

Can Nesimi ARI finder

References

www.usom.gov.tr/bildirim/tr-25-0396

cve.org (CVE-2025-8855)

nvd.nist.gov (CVE-2025-8855)

Download JSON