CVE-2025-4320

Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

05 Jun 2026, 16:16

Type Values Removed Values Added
Summary (en) Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
  • () https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0005 -

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Omisión de autenticación por debilidad primaria. Vulnerabilidad de mecanismo débil de recuperación de contraseña para contraseña olvidada en Birebirsoft Software y Technology Solutions Sufirmam permite omitir la autenticación, explotar la recuperación de contraseña. Este problema afecta a Sufirmam: hasta el 23012026. NOTA: Antes de la divulgar esta vulnerabilidad se contactó con el proveedor, pero no respondió de ninguna manera.

23 Jan 2026, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 13:15

Updated : 2026-06-17 09:33


NVD link : CVE-2025-4320

Mitre link : CVE-2025-4320

CVE.ORG link : CVE-2025-4320


JSON object : View

Products Affected

No product.

CWE
CWE-305

Authentication Bypass by Primary Weakness

CWE-640

Weak Password Recovery Mechanism for Forgotten Password