Back

CRITICAL

Hundred Plus|EIP Plus - Weak Password Recovery Mechanism

Published Nov 10, 2025

Description

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

Affected products

Remediation

Vendor solution

Update to version RELEASE_240626 or later.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Nov 10, 2025
Updated Nov 12, 2025
Reserved Nov 7, 2025
CISA Vulnrichment
Updated Nov 10, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a