CVE-2025-8025Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-11: 2Technical Details · 2026-02-11: 202-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-8025: CRITICAL] Critical vulnerability in Dinosoft ERP allows unauthorized access to sensitive functions. Missing authentication and access control issues impact versions &lt; 3.0.1 through 11022026.#cve,CVE-2025-8025,#cybersecurity https://cvefind.com/CVE-2025-8025

    Post summary

    CVE-2025-8025 is a critical authentication bypass vulnerability in Dinosoft ERP affecting versions below 3.0.1, but no PoC, exploit, patch, or active exploitation evidence is mentioned.

    0000084
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-8025 - Critical Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by A... https://www.thehackerwire.com/vulnerability/CVE-2025-8025/ https://t.co/fNpdRhGNNf

    Post summary

    The tweet announces the critical CVE-2025-8025 vulnerability in Dinosoft ERP, detailing missing authentication and improper access control, but does not provide a PoC, exploit, or patch information.

    0000063
    112 followersView on X

Explore more