CVE ID | CVE-2025-4049 |
Publication date | 21 July 2025 |
Vendor | SIGNUM-NET |
Product | FARA |
Vulnerable versions | All through 5.0.80.34 |
Vulnerability type (CWE) | Use of Hard-coded Credentials (CWE-798) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in SIGNUM-NET FARA software and participated in coordination of its disclosure.
The vulnerability CVE-2025-4049: Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate a local-stored database. This issue affects FARA: through 5.0.80.34.
Credits
We thank Mateusz Sirko for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.