Back to overview

CVE-2025-4320

CRITICAL
10.0
CVSS 3.1
Description
Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2025-4320
State
PUBLISHED
Assigner
TR-CERT
Reserved
2025-05-05 14:16 UTC
Published
2026-01-23 12:26 UTC
Last updated
2026-06-05 14:51 UTC
Primary CWE
CWE-305
CWE-305 Authentication Bypass by Primary Weakness
Vendor / Product
Birebirsoft Software and Technology Solutions / Sufirmam
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Birebirsoft Software and Technology Solutions Sufirmam 0 ≤ 23012026
Weakness (CWE)
CWESourceDescription
CWE-305 cna CWE-305 Authentication Bypass by Primary Weakness
CWE-640 cna CWE-640 Weak Password Recovery Mechanism for Forgotten Password
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview