🔐 CVE Alert

CVE-2025-41257

MEDIUM 4.8

Suprema BioStar 2 Insecure Password Change

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.

CWE CWE-20
Vendor suprema
Product biostar 2
Published Mar 4, 2026
Last Updated Mar 9, 2026
Stay Ahead of the Next One

Get instant alerts for suprema biostar 2

Be the first to know when new medium vulnerabilities affecting suprema biostar 2 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Suprema / BioStar 2
2.9.11.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251104-02_Suprema_BioStar_2_Insecure_Password_Change supremainc.com: https://www.supremainc.com/en/platform/hybrid-security-platform-biostar-2.asp

Credits

Jakob Hagl (SBA Research) Marija Radosavljević (SBA Research) Fabian Funder (SBA Research)