CVE-2025-10643
BaseFortify
Publication date: 2025-09-17
Last updated on: 2025-09-19
Assigner: Zero Day Initiative
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wondershare | repairit | 6.5.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Wondershare Repairit involves incorrect permission assignment that allows remote attackers to bypass authentication without needing to log in. The flaw is related to the permissions granted to a storage account token, which an attacker can exploit to gain unauthorized access.
How can this vulnerability impact me? :
The vulnerability can allow attackers to bypass authentication and gain unauthorized access to the system, potentially leading to exposure or manipulation of sensitive data. Since authentication is not required to exploit it, the risk of unauthorized access is high.