LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-15025

CVE-2025-15025 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 14, 2026

Yordam Library Automation System - Authorization Bypass

Published: May 14, 2026Updated: May 14, 2026Remote Exploitable

Overview

Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System from v.21.6 before v.22.1 contains an authorization bypass caused by user-controlled key vulnerability, letting attackers exploit trusted identifiers to bypass authorization, exploit requires crafted user input.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can bypass authorization, gaining unauthorized access to restricted resources or functions.

Mitigation

Update to version 22.1 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 14, 2026

🟠 CVE-2025-15025 - High (8.8) Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploitation of Trusted Identifiers. This issue a... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-15025/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 14, 2026

🟠 CVE-2025-15025 - High (8.8) Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploitation of Trusted Identifiers. This issue a... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-15025/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-15025
Severity
High
CVSS Score
8.8
Type
broken_access_control
Status
rejected
EPSS
0.0%
Social Posts
2

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days