go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Simopro Technology|WinMatrix3 Web package - Insecure Direct Object Reference

TVN ID TVN-202507010
CVE ID CVE-2025-7919
CVSS 6.5 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products WinMatrix Web version 1.2.39.5 and earlier
Description WinMatrix3 Web package developed by Simopro Technology has an Insecure Direct Object Reference vulnerability, allowing attackers with regular privileges to manipulate a specific parameter to obtain other users' sensitive information, including encrypted password data.
Solution Update AP to version 3.8.52.5 (Web 1.2.39.5) and install the hotfix, or update AP to version 3.9.1 (Web 1.3.1) or later
Credit Linwz(DEVCORE)
Public Date 2025-07-21
Top