CVE-2026-25607
Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.7
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-261
- Published
- 2026-05-22
- Last modified
- 2026-05-22
Affected products
- Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy STER
Weakness type
Related vulnerabilities
- CVE-2026-63424 — During an internal security assessment, an improperly protected key was discovered in Lenovo Dock...
- CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-40639 — Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated...
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż
- CVE-2024-52334 — A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected...
- CVE-2025-67652 — AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password