go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Digiwin|EasyFlow .NET and EasyFlow AiNet - Missing Authentication

TVN ID TVN-202510007
CVE ID CVE-2025-11949
CVSS 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products EasyFlow .NET version 6.6.19 and earlier
EasyFlow AiNet version 8.1.1 and earlier
Description EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to obtain database administrator credentials via a specific functionality.
Solution Update EasyFlow.NET to version 6.6.19 and install the patch 20250520
Update EasyFlow AiNet to version 8.1.1 and install the patch 20250520
Credit Sam Huang(CHT Security)
Public Date 2025-10-20
Top