CRITICAL🇵🇱 Wersja polska

CVE-2025-12870

CVSS 9.3v4.0pub. 2025-11-12upd. 2025-11-18

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-1390 (Weak Authentication) involves a flawed authentication mechanism in the a+HRD application. An unauthorized attacker can send specially crafted network packets to the system, which result in the server returning a valid administrator access token. The obtained token can then be used to log in and perform operations with the highest privilege level in the application.

Impact

An attacker gains full administrative access to the a+HRD system, enabling them to read, modify, or delete personnel and HR data stored in the system. It is also possible to further seize control over organizational resources accessible from the compromised application level.

Mitigation & patch

Apply patches available from the vendor in accordance with the references — detailed information on patched software versions is available in the TWCERT bulletin (https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html) and in the CHT Security security advisory. Until updates are deployed, it is recommended to restrict application access at the network level (firewall) to trusted IP addresses only.

Who is affected

The a+HRD system developed by aEnrich (aEnrich Technology); specific vulnerable versions are indicated in the vendor references and in the TWCERT bulletin.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Aenrich A\+hrd

    APP
    Aenrich
    ≤ 7.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-12871CRITICAL9.3PL ✓same product

Aenrich A+HRD – obejście uwierzytelnienia przez fałszywe tokeny administratora

CVE-2025-0585CRITICAL9.8PL ✓same product

SQL Injection w Aenrich A+HRD — nieuwierzytelniony zdalny dostęp do bazy danych

CVE-2023-20852CRITICAL9.8PL ✓same product

Deserializacja niezaufanych danych w aEnrich a+HRD — RCE bez uwierzytelnienia

CVE-2023-20853CRITICAL9.8PL ✓same product

Deserializacja niezaufanych danych w aEnrich a+HRD (MSMQ) — RCE bez uwierzytelnienia

CVE-2022-39041CRITICAL9.8PL ✓same product

SQL Injection w aEnrich a+HRD — nieuwierzytelniony dostęp do bazy danych