Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 04 Mar 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise. | |
| Title | Suprema BioStar 2 Insecure Password Change | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sba-research
Published:
Updated: 2026-03-04T22:43:53.077Z
Reserved: 2025-04-16T09:37:50.631Z
Link: CVE-2025-41257
No data.
Status : Received
Published: 2026-03-04T23:16:09.713
Modified: 2026-03-04T23:16:09.713
Link: CVE-2025-41257
No data.
OpenCVE Enrichment
No data.
Weaknesses