Authentication Bypass Vulnerability in Wondershare Repairit
CVE-2025-10644

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-10644?

Wondershare Repairit is susceptible to an authentication bypass vulnerability related to improper permissions granted to an SAS token. This misconfiguration allows remote attackers to circumvent authentication controls, enabling them to exploit the system effectively. By leveraging this flaw, adversaries can potentially execute arbitrary code and initiate supply-chain attacks against users' endpoints. Organizations utilizing Wondershare Repairit should assess their security posture and apply necessary mitigations to safeguard against potential threats stemming from this vulnerability.

Affected Version(s)

Repairit 6.5.2

References

CVSS V3.0

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10644 : Authentication Bypass Vulnerability in Wondershare Repairit