The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
References
| Link | Resource |
|---|---|
| https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html | Third Party Advisory |
| https://www.twcert.org.tw/tw/cp-132-10486-a3459-1.html | Third Party Advisory |
| https://www.chtsecurity.com/news/b97e8337-6b0c-43e8-8e8c-187b7c0e13c2 | Press/Media Coverage Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-11-12 08:15
Updated : 2025-11-18 19:31
NVD link : CVE-2025-12870
Mitre link : CVE-2025-12870
CVE.ORG link : CVE-2025-12870
JSON object : View
Products Affected
aenrich
- a\+hrd
CWE
CWE-1390
Weak Authentication
