CVE-2025-12623 Details
Description
A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/com/fuint/module/clientApi/controller/ClientSignController.java of the component Authentication Token Handler. Such manipulation leads to authorization bypass. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
An authentication bypass vulnerability has been identified in Fushengqian Fuint versions prior to 41e26be8a2c609413a0feaa69bdad33a71ae8032. The issue arises in the ClientSignController.java file, specifically within the Authentication Token Handler component. The vulnerability allows unauthorized access to user accounts by overwriting a securely generated authentication token with the user's mobile phone number. This flaw can be exploited remotely and is considered complex, although a public exploit is available.
The vulnerability can be fixed by removing the line of code that overwrites the secure token with the user's phone number. After applying this fix, it's recommended to force all users to re-authenticate and monitor for any signs of exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 3, 2025CISA-ADP
Assessed Nov 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/fushengqian/fuint/issues/67 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://vuldb.com/?ctiid.330915 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.330915 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.678911 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fushengqian fuint | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Nov 3, 2025 | New CVE Received | [email protected] |
Volerion