CVE-2025-12866: Hundred Plus|EIP Plus - Weak Password Recovery Mechanism
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12866?
CVE-2025-12866 is classified as a medium severity vulnerability due to its potential to allow unauthorized password resets.
How do I fix CVE-2025-12866?
To fix CVE-2025-12866, implement stronger password recovery mechanisms that include rate limiting and additional verification methods.
Who is affected by CVE-2025-12866?
CVE-2025-12866 affects users of the Hundred Plus EIP Plus software that utilizes weak password recovery features.
Can CVE-2025-12866 be exploited remotely?
Yes, CVE-2025-12866 can be exploited by unauthenticated remote attackers who can predict or brute-force the password reset functionality.
What types of attacks are possible with CVE-2025-12866?
Possible attacks with CVE-2025-12866 include account takeover through unauthorized password resets.