CVE-2025-10609 PUBLISHED

Hardcoded Credentials in Logo Software's TigerWings ERP

Assigner: TR-CERT
Reserved: 17.09.2025 Published: 03.10.2025 Updated: 05.06.2026

Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read Sensitive Constants Within an Executable.

This issue affects TigerWings ERP: from 01.01.00 before 3.03.00.

Metrics

CVSS Vector: CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
CVSS Score: 5.9

Product Status

Vendor Logo Software Inc.
Product TigerWings ERP
Versions Default: unaffected
  • affected from 01.01.00 to 3.03.00 (excl.)

Credits

  • Oguzhan Karasu finder

References

Problem Types

  • CWE-798 Use of Hard-coded Credentials CWE

Impacts

  • CAPEC-191 Read Sensitive Constants Within an Executable