CVE-2025-8853

critical

Description

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

References

https://www.twcert.org.tw/tw/cp-132-10319-adc18-1.html

https://www.twcert.org.tw/en/cp-139-10320-ad540-2.html

https://www.chtsecurity.com/news/a9a90f0b-c2cb-4c66-b3d1-bc7f252fd108

https://www.chtsecurity.com/news/8618a2f0-390a-4506-9ff8-a9e74030d19e

Details

Source: Mitre, NVD

Published: 2025-08-11

Updated: 2025-08-11

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.00184