codecanyon.net
https://codecanyon.net/item/zender-android-mobile-devices-as-sms-gateway-saas-platform/26594230 CVE-2025-56676
MEDIUM
Record summary
CVE-2025-56676 has a selected CVSS score of 5.4 (medium).
Description
TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary password or reset token issued to one user can be used to log in as another user, due to improper validation of token-user linkage. This allows remote attackers to gain unauthorized access to any user account by exploiting the password reset mechanism. The vulnerability occurs because the reset token is not correctly bound to the requesting account and is accepted for other user emails during login, enabling privilege escalation and information disclosure.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 1, 2025 · Source: CVE List
References
4darklotus.medium.com
https://darklotus.medium.com/cve-2025-56676-critical-vulnerability-in-zender-gateway-allows-account-takeover-2b5bcb50c762 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-56676 previews.titansystems.ph
https://previews.titansystems.ph/zender/dashboard/auth