CVE-2025-12866 PUBLISHED

Hundred Plus|EIP Plus - Weak Password Recovery Mechanism

Assigner: twcert
Reserved: 07.11.2025 Published: 10.11.2025 Updated: 12.11.2025

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Hundred Plus
Product EIP Plus
Versions Default: unaffected
  • affected from 0 to RELEASE_240626 (excl.)

Solutions

Update to version RELEASE_240626 or later.

References

Problem Types

  • CWE-640 Weak Password Recovery Mechanism for Forgotten Password CWE

Impacts

  • CAPEC-50 Password Recovery Exploitation