CVE Explorer
CVE-2025-9060
A vulnerability has been found in the MSoft MFlash
application that allows
execution of arbitrary code on the server. The issue occurs in the
integration configuration functionality that is only available to
MFlash
administrators. The vulnerability is related to insufficient validation
of parameters when setting up security components.
This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"MFlash","vendor":"MSoft","versions":[{"status":"affected","version":"8.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9211f9e48990d04f89482135216cdc27b655b6427dfe83d083461b80ffb20a0f · sha256:5d20bb5662dab712… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9211f9e48990d04f89482135216cdc27b655b6427dfe83d083461b80ffb20a0f · sha256:5d20bb5662dab712… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9211f9e48990d04f89482135216cdc27b655b6427dfe83d083461b80ffb20a0f · sha256:5d20bb5662dab712… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://github.com/klsecservices/Advisories/blob/master/K-MSoft-2025-002.md"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9211f9e48990d04f89482135216cdc27b655b6427dfe83d083461b80ffb20a0f · sha256:5d20bb5662dab712… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.