9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
AI Analysis
Weak Password Recovery Mechanism vulnerability allowing unauthenticated remote attackers to predict or brute-force the 'forgot password' link
Basic Information
ID
CVE-2025-12866
Source
twcert
Published
Nov 10, 2025 at 02:45
Affected Product
Vendor
Hundred Plus
Product
EIP Plus
Affected Versions
Hundred Plus EIP Plus 0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Hundred Plus
Product
EIP Plus