CVE-2025-9060

CRITICAL

MSoft MFlash 8.0 - Authenticated Remote Code Execution via Integration Configuration

Title source: llm
STIX 2.1

Description

A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.

Scores

CVSS v3 9.1
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
MSoft/MFlash 8.0
Published Aug 15, 2025
Tracked Since Feb 18, 2026