CVE-2025-9342: IDOR in Anadolu Hayat Emeklilik's AHE Mobile
Published Sep 23, 2025
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privilege Abuse.
This issue affects AHE Mobile: from 1.9.7 before 1.9.9.
Affected Software
1 affected component
Anadolu Hayat Emeklilik AHE Mobile>=1.9.7<1.9.9
Event History
Sep 23, 2025
CVE Published
via MITRE·09:18 AM
Data Sourced
via MITRE·09:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Feb 27, 57989
Event
via FIRST·09:17 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9342?
CVE-2025-9342 is categorized as a high severity vulnerability due to the potential for privilege abuse.
2
How do I fix CVE-2025-9342?
To mitigate CVE-2025-9342, users should update the AHE Mobile application to version 1.9.9 or later.
3
What does CVE-2025-9342 affect?
CVE-2025-9342 affects the AHE Mobile application developed by Anadolu Hayat Emeklilik Inc. versions from 1.9.7 before 1.9.9.
4
What type of vulnerability is CVE-2025-9342?
CVE-2025-9342 is an authorization bypass vulnerability that allows user-controlled key exploitation.
5
Is CVE-2025-9342 present in all versions of AHE Mobile?
No, CVE-2025-9342 is only present in AHE Mobile versions from 1.9.7 to 1.9.8.