CVE-2025-10644
Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the permissions granted to an SAS token. An attacker can leverage this vulnerability to launch a supply-chain attack and execute arbitrary code on customers' endpoints. Was ZDI-CAN-26892.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- Base score: 9.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.00%
- Percentile among all scored CVEs: 87
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access60 %
Inferred by deterministic rules from the CVSS vector and CWE. Indicative only.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-266
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-10644",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-10644",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-09-18T15:20:57.567090Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.4,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "zdi-disclosures@trendmicro.com",
"affectedData": [
{
"vendor": "Wondershare",
"product": "Repairit",
"versions": [
{
"status": "affected",
"version": "6.5.2"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-09-17T21:15:37.807",
"references": [
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-25-896/",
"tags": [
"Third Party Advisory"
],
"source": "zdi-disclosures@trendmicro.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"description": [
{
"lang": "en",
"value": "CWE-266"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the permissions granted to an SAS token. An attacker can leverage this vulnerability to launch a supply-chain attack and execute arbitrary code on customers' endpoints. Was ZDI-CAN-26892."
},
{
"lang": "es",
"value": "Vulnerabilidad de omisión de autenticación por asignación incorrecta de permisos del token SAS de Wondershare Repairit. Esta vulnerabilidad permite a atacantes remotos omitir la autenticación en Wondershare Repairit. No se requiere autenticación para explotar esta vulnerabilidad.\n\nLa falla específica reside en los permisos otorgados a un token SAS. Un atacante puede aprovechar esta vulnerabilidad para lanzar un ataque a la cadena de suministro y ejecutar código arbitrario en los puntos finales de los clientes. Fue ZDI-CAN-26892."
}
],
"lastModified": "2026-09-26T00:10:00.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wondershare:repairit:6.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A001D7E-B543-435F-AB5B-E219DE226162"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "zdi-disclosures@trendmicro.com"
}