CVE ID | CVE-2025-3920 |
Publication date | 07 July 2025 |
Vendor | SUR-FBD CMMS |
Product | SUR-FBD CMMS |
Vulnerable versions | All through 2025.03.27 |
Vulnerability type (CWE) | Use of Hard-coded Password (CWE-259) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in SUR-FBD CMMS software and participated in coordination of its disclosure.
The vulnerability CVE-2025-3920 was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the system or the application's installation directory could extract these credentials, potentially leading to a complete compromise of the application's administrative functions. This issue was fixed in version 2025.03.27 of the SUR-FBD CMMS software.
Credits
We thank Thomas Hayen (Easi) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.