Junglewise Threat Intelligence

CVE-2025-10161: Turkguven Perfektive authentication bypass and brute force vulnerability

CVE-2025-10161 · Severity: high · CVSS 7.3 · Published 2025-11-11

Executive brief

Turkguven Perfektive, a business management and operations platform, contains security flaws in its login and authentication mechanisms. These vulnerabilities allow unauthorized individuals to bypass security checks or perform automated password-guessing attacks. If exploited, an attacker could gain unauthorized access to the system, potentially compromising sensitive business data or disrupting operations.

Technical details

Turkguven Perfektive contains multiple authentication-related vulnerabilities including CWE-307 (Improper Restriction of Excessive Authentication Attempts), CWE-602 (Client-Side Enforcement of Server-Side Security), and CWE-807 (Reliance on Untrusted Inputs in a Security Decision). The application fails to properly rate-limit login attempts on the server side and relies on client-side logic or untrusted inputs to make security decisions. A remote, unauthenticated attacker can exploit these flaws to perform brute-force attacks or bypass authentication mechanisms entirely. The issue is resolved in Version 12574 Build 2701.

Affected products

  • Turkguven Software Technologies Inc. Perfektive before Version 12574 Build 2701

Timeline

  • 2025-11-11: advisory: Initial publication by TR-CERT/USOM
  • 2025-11-11: disclosed

References