CVE-2025-14696
MEDIUMShenzhen Sixun Software Sixun Shanghui Group Business Management Sy...
Title source: llmDescription
A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulation leads to weak password recovery. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
References (5)
Scores
CVSS v3
5.3
EPSS
0.0004
EPSS Percentile
13.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-640
Status
draft
Timeline
Published
Dec 15, 2025
Tracked Since
Feb 18, 2026