Database Manipulation Vulnerability in SIGNUM-NET FARA Product
CVE-2025-4049

8.6HIGH

Key Information:

Vendor

Signum-net

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-4049?

A vulnerability in SIGNUM-NET's FARA application is identified where hard-coded SQLite credentials are utilized across all affected installations. This flaw permits unauthorized access, enabling potential attackers to read and manipulate local-stored databases. The issue is present in FARA versions up to and including 5.0.80.34, highlighting a significant security risk for users relying on this software for data management. It is crucial for organizations to review their deployments and consider upgrading or applying mitigation strategies to safeguard their data integrity.

Affected Version(s)

FARA 0 <= 5.0.80.34

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mateusz Sirko
.
CVE-2025-4049 : Database Manipulation Vulnerability in SIGNUM-NET FARA Product