Content:
Forwarded from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202511-00000007
[EIP Plus - Weak Password Recovery Mechanism] (CVE-2025-12866, CVSS: 9.8) An unauthenticated remote attacker can predict or brute-force the 'forgot password' link to successfully modify arbitrary user passwords.
Affected Platforms:
Recommended Measures:
References:
-
Computer and Communications Center
Network Systems Group