CVE-2025-41257

MEDIUM

Suprema BioStar 2 2.9.11.6 - Auth Bypass

Title source: llm
STIX 2.1

Description

Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.

Scores

CVSS v3 4.8
EPSS 0.0002
EPSS Percentile 3.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Published Mar 04, 2026
Tracked Since Mar 05, 2026