The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
References
| Link | Resource |
|---|---|
| https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html | Third Party Advisory |
| https://www.twcert.org.tw/tw/cp-132-10486-a3459-1.html | Third Party Advisory |
| https://www.chtsecurity.com/news/b97e8337-6b0c-43e8-8e8c-187b7c0e13c2 | Press/Media Coverage Third Party Advisory |
Configurations
History
18 Nov 2025, 19:31
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Aenrich
Aenrich a\+hrd |
|
| CPE | cpe:2.3:a:aenrich:a\+hrd:*:*:*:*:*:*:*:* | |
| References | () https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html - Third Party Advisory | |
| References | () https://www.twcert.org.tw/tw/cp-132-10486-a3459-1.html - Third Party Advisory | |
| References | () https://www.chtsecurity.com/news/b97e8337-6b0c-43e8-8e8c-187b7c0e13c2 - Press/Media Coverage, Third Party Advisory |
12 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Nov 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-12 08:15
Updated : 2025-11-18 19:31
NVD link : CVE-2025-12870
Mitre link : CVE-2025-12870
CVE.ORG link : CVE-2025-12870
JSON object : View
Products Affected
aenrich
- a\+hrd
CWE
