Authentication Bypass Vulnerability in Wondershare Repairit
CVE-2025-10644
9.4CRITICAL
What is CVE-2025-10644?
Wondershare Repairit is susceptible to an authentication bypass vulnerability related to improper permissions granted to an SAS token. This misconfiguration allows remote attackers to circumvent authentication controls, enabling them to exploit the system effectively. By leveraging this flaw, adversaries can potentially execute arbitrary code and initiate supply-chain attacks against users' endpoints. Organizations utilizing Wondershare Repairit should assess their security posture and apply necessary mitigations to safeguard against potential threats stemming from this vulnerability.
Affected Version(s)
Repairit 6.5.2
References
CVSS V3.0
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
