CVE-2025-12866
CRITICALHundred Plus EIP Plus < RELEASE_240626 - Unauthenticated Weak Password Recovery Mechanism
Title source: llmDescription
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
References (3)
Core 3
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-10490-2534b-1.html
Various Sources third-party-advisory
https://www.twcert.org.tw/en/cp-139-10491-004b0-2.html
Scores
CVSS v3
9.8
EPSS
0.0045
EPSS Percentile
35.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-640
Status
published
Products (1)
Hundred Plus/EIP Plus
< RELEASE_240626
Published
Nov 10, 2025
Tracked Since
Feb 18, 2026