go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Flowring Technology Agentflow - Account Lockout Bypass

TVN ID TVN-202505001
CVE ID CVE-2025-3709
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Agentflow 4.0
Description Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
Solution Log in to the CRM and download the patch.
Credit Lucas Yang (SIHAN YANG), Luke Xie(Xie Hung You)
Public Date 2025-05-02
Top