CVE-2025-41257
Received
Received - Intake
Password Reset Bypass in Suprema BioStar 2 Enables Unauthorized Access
Publication date: 2026-03-04
Last updated on: 2026-03-09
Assigner: sba-research
Description
Description
Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| suprema | biostar_2 | 2.9.11.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |