Floragasse 7 – 5th floor, 1040 Vienna

News

SBA Security Advisory – Suprema BioStar 2 Insecure Password Change (CVE-2025-41257)

Vulnerability Overview

Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.

  • Type of Vulnerability: Improper Input Validation
  • Fixed in Version: Not yet
  • CVE ID: CVE-2025-41257
  • CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  • CVSS Base Score: 4.8 (Medium)

Recommended Countermeasure

We are not aware of a released fix yet. However, the vendor has a patch available for version 2.9.11. Please contact the vendor.

Links

Full Security Advisory

Credits

Jakob Hagl (SBA Research)
Marija Radosavljević (SBA Research)
Fabian Funder (SBA Research)

The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.