Hard-coded Credential Vulnerability in SUR-FBD CMMS by SUR-FBD
CVE-2025-3920

8.5HIGH

Key Information:

Vendor
CVE Published:
7 July 2025

What is CVE-2025-3920?

A significant security issue has been discovered in SUR-FBD CMMS, where hard-coded administrative credentials are embedded within a compiled DLL file. This flaw allows an attacker with access to the local system or the application's installation directory to extract these credentials, potentially granting unauthorized administrative control over the application. The vulnerability has been addressed in the release of version 2025.03.27, underscoring the importance of software updates to mitigate such risks.

Affected Version(s)

SUR-FBD CMMS 0 < 2025.03.27

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Hayen (Easi)
.
CVE-2025-3920 : Hard-coded Credential Vulnerability in SUR-FBD CMMS by SUR-FBD