Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Mar 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Supremainc
Supremainc biostar 2 |
|
| Vendors & Products |
Supremainc
Supremainc biostar 2 |
Wed, 04 Mar 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise. | |
| Title | Suprema BioStar 2 Insecure Password Change | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sba-research
Published: 2026-03-04T22:43:53.077Z
Updated: 2026-03-09T20:59:30.756Z
Reserved: 2025-04-16T09:37:50.631Z
Link: CVE-2025-41257
Updated: 2026-03-09T20:59:19.397Z
Status : Awaiting Analysis
Published: 2026-03-04T23:16:09.713
Modified: 2026-03-09T21:16:10.490
Link: CVE-2025-41257
No data.
ReportizFlow