CVE-2025-41257
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
04/03/2026
Last modified:
04/03/2026
Description
Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM



