Content:
Forwarded from National Information Security Information Sharing and Analysis Center Security Alert NISAC-200-202511-00000149
Researchers have discovered an Authentication Abuse vulnerability (CVE-2025-12870 and CVE-2025-12871) in Aenrich Digital Technology eHRD. An unauthenticated remote attacker can obtain or self-generate administrative privilege credentials and use them to access the system with administrator privileges. Please confirm and patch as soon as possible.
Affected Platforms:
Recommended Measures:
References:
-
-
-
Computer and Communications Center
Network Systems Group