216.73.216.226

CVE-2025-41257

· Published 04/03/2026 23:16 · Modified 05/03/2026 19:38

Labels: CVE-2025-41257 1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a2026-03-04CVE-2025-41257CWE-20

Essential information

Published
04/03/2026 23:16
Modified
05/03/2026 19:38
Author
Creator
CVSS
4.8 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a
NVD
View on NVD

Affected products (CPE)

ProductCPE
suprema / biostar 2 cpe:2.3:a:suprema:biostar_2:2.9.11.6:*:*:*:*:*:*:*

References