# CVE-2026-25607

## Summary

- **CVE ID:** CVE-2026-25607
- **Severity:** MEDIUM
- **CVSS Score:** 5.7 (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-261
- **Published:** May 22, 2026
- **Last Modified:** May 22, 2026

## Description

Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.

This issue was fixed in version 9.5.

## Affected Products

- Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy — STER (0)

## References

- [CNA](https://cert.pl/posts/2026/05/CVE-2026-25606)
- [CNA](https://www.ciop.pl/CIOPPortalWAR/appmanager/ciop/pl?_nfpb=true&_pageLabel=P52000165211572544981480)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 0.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._