Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
References
Configurations
No configuration.
History
09 Mar 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251104-02_Suprema_BioStar_2_Insecure_Password_Change - |
04 Mar 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-04 23:16
Updated : 2026-03-09 21:16
NVD link : CVE-2025-41257
Mitre link : CVE-2025-41257
CVE.ORG link : CVE-2025-41257
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
