CVE-2025-11949

7.5

Digiwin · EasyFlow .NET and EasyFlow AiNet

Digiwin EasyFlow .NET and AiNet suffer from a missing authentication vulnerability that allows unauthenticated remote attackers to obtain database administrator credentials.

Executive summary

A critical missing authentication vulnerability in Digiwin EasyFlow allows unauthenticated remote attackers to gain unauthorized access to database administrator credentials.

Vulnerability

The software fails to implement proper authentication checks for critical functionality, enabling an unauthenticated remote attacker to retrieve sensitive database administrator credentials.

Business impact

The exposure of database administrator credentials poses a severe risk to organizational data integrity and confidentiality. A successful exploit could lead to full unauthorized access to the underlying databases, potentially resulting in data exfiltration, modification, or total system compromise. Given the CVSS score of 7.5, this vulnerability represents a high-risk entry point that could facilitate broader network lateral movement.

Remediation

Immediate Action: Update EasyFlow .NET to version 6.6.19 and apply patch 20250520, and update EasyFlow AiNet to version 8.1.1 and apply patch 20250520.

Proactive Monitoring: Monitor database access logs for unusual queries or authentication attempts originating from unexpected IP addresses.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to block unauthorized access attempts to administrative endpoints.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

This vulnerability presents a significant security risk due to the potential for complete database compromise by unauthenticated actors. Organizations utilizing Digiwin EasyFlow must prioritize the application of the specified patches immediately. Failure to address this flaw leaves critical infrastructure exposed to unauthorized administrative access.

More Digiwin CVEs

Sources