PT-2025-46573 · A+Hrd · A+Hrd

Published

2025-11-12

·

Updated

2025-11-13

·

CVE-2025-12871

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aEnrich a+HRD (affected versions not specified)
Description The a+HRD software contains an authentication issue that allows unauthenticated remote attackers to create administrator access tokens. These tokens can then be used to gain access to the system with elevated privileges. The vulnerability involves authentication abuse.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-12871

Affected Products

A+Hrd