PT-2025-40342 · Unknown · Poscube Assist

Published

2025-10-02

·

Updated

2025-10-02

·

CVE-2025-0642

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions PosCube Assist versions through 10.02.2025
Description The software contains hard-coded credentials and allows authorization bypass through user-controlled keys, potentially enabling excavation and authentication bypass.
Recommendations Update to a version later than 10.02.2025.

Fix

IDOR

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-0642

Affected Products

Poscube Assist