Junglewise Threat Intelligence

CVE-2025-0642: PosCube Assist auth bypass via hard-coded credentials and IDOR

CVE-2025-0642 · Severity: medium · CVSS 6.3 · Published 2025-10-02

Executive brief

PosCube Assist, a software solution used for business operations, contains security flaws that could allow unauthorized users to bypass login protections. By exploiting hard-coded credentials or manipulating user-controlled keys, an attacker could gain access to sensitive data or perform unauthorized actions within the system. This could lead to the exposure of confidential business information and a loss of control over the application's security.

Technical details

The vulnerability in PosCube Assist stems from two primary weaknesses: the use of hard-coded credentials (CWE-798) and an authorization bypass via user-controlled keys (CWE-639), often referred to as Insecure Direct Object Reference (IDOR). An attacker with low-privileged network access can exploit these flaws to bypass authentication mechanisms or access resources belonging to other users by manipulating identifiers. The attack requires minimal technical complexity and some user interaction, potentially leading to high confidentiality impact. The issue affects all versions of the Assist software released through February 10, 2025.

Affected products

  • PosCube Hardware Software and Consulting Ltd. Co. Assist through 10.02.2025

Timeline

  • 2025-10-02: disclosed
  • 2025-10-02: advisory

References