CVE-2025-10174 PUBLISHED

Improper Access Control in Pan Software's PanCafe Pro

Assigner: TR-CERT
Reserved: 09.09.2025 Published: 11.02.2026 Updated: 11.02.2026

Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding.This issue affects PanCafe Pro: from < 3.3.2 through 23092025.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
CVSS Score: 8.3

Product Status

Vendor Pan Software & Information Technologies Ltd.
Product PanCafe Pro
Versions Default: unaffected
  • affected from < 3.3.2 to 23092025 (incl.)

Credits

  • Muhammed İbrahim TEKİN finder
  • Teknopark İstanbul Mesleki Teknik Anadolu Lisesi coordinator

References

Problem Types

  • CWE-319 Cleartext Transmission of Sensitive Information CWE

Impacts

  • CAPEC-125 Flooding