PT-2025-52456 · Unknown · Turms Server

·

CVE-2025-66910

·

Published

2025-12-19

·

Updated

2026-01-02

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Turms Server versions prior to 0.10.0-SNAPSHOT
Description The software stores administrator passwords in plaintext within memory, specifically in the rawPassword field of AdminInfo objects, to improve authentication speed. This bypasses the bcrypt protection normally used. An attacker with local system access could obtain these passwords through methods like memory dumps or heap analysis.
Recommendations Update to a version newer than 0.10.0-SNAPSHOT.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66910

Affected Products

Turms Server