# CVE-2025-8853

## Summary

- **CVE ID:** CVE-2025-8853
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-290
- **Published:** Aug 11, 2025
- **Last Modified:** Mar 12, 2026

## Description

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

## Affected Products

- 2100 Technology — Official Document Management System (5.0.89.0)
- 2100 Technology — Official Document Management System (5.0.89.1)
- 2100 Technology — Official Document Management System (5.0.89.2)

## References

- [CNA](https://www.twcert.org.tw/tw/cp-132-10319-adc18-1.html)
- [CNA](https://www.twcert.org.tw/en/cp-139-10320-ad540-2.html)
- [CNA](https://www.chtsecurity.com/news/8618a2f0-390a-4506-9ff8-a9e74030d19e)
- [CNA](https://www.chtsecurity.com/news/a9a90f0b-c2cb-4c66-b3d1-bc7f252fd108)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.69%
- **EPSS Percentile:** 50.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._