ZDI-25-895: (0Day) Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists within the permissions granted to a storage account token. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.1. The following CVEs are assigned: CVE-2025-10643.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-895?
ZDI-25-895 is considered a critical vulnerability due to its ability to allow remote attackers to bypass authentication.
How do I fix ZDI-25-895?
To fix ZDI-25-895, it is recommended to update Wondershare Repairit to the latest version that includes security patches.
What type of vulnerability is ZDI-25-895?
ZDI-25-895 is an authentication bypass vulnerability that enables unauthorized access to affected installations.
Who is affected by ZDI-25-895?
Users of Wondershare Repairit are affected by the ZDI-25-895 vulnerability if they have not updated their software.
Can ZDI-25-895 be exploited remotely?
Yes, ZDI-25-895 can be exploited remotely as it does not require authentication.