Missing Authentication Vulnerability in EasyFlow .NET and AiNet by Digiwin
CVE-2025-11949

8.7HIGH

Key Information:

Vendor

Digiwin

Vendor
CVE Published:
21 October 2025

What is CVE-2025-11949?

The EasyFlow .NET and EasyFlow AiNet products developed by Digiwin contain a significant security vulnerability that allows unauthenticated remote attackers to exploit specific functionalities. This vulnerability enables unauthorized individuals to acquire database administrator credentials, potentially leading to unauthorized access to sensitive data and system controls. Organizations using these products are advised to assess their security measures and implement necessary patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

EasyFlow .NET 0 <= 6.6.19

EasyFlow AiNet 0 <= 8.1.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11949 : Missing Authentication Vulnerability in EasyFlow .NET and AiNet by Digiwin