PT-2025-38264 · Wondershare · Wondershare Repairit
Alfredo Oliveira
+1
·
Published
2025-04-30
·
Updated
2025-10-08
·
CVE-2025-10643
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Wondershare Repairit version 6.5.2
Wondershare Repairit (affected versions not specified)
Description
The software contains an authentication bypass issue stemming from incorrect permission assignments within a storage account token. This allows remote attackers to bypass authentication without needing to log in. The flaw enables attackers to access the system by exploiting the permissions associated with the token. Multiple reports indicate the potential for supply chain risks, including the ability to swap AI models. No estimated number of affected devices or real-world incidents beyond the discovery of the flaw have been reported.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wondershare Repairit