Junglewise Threat Intelligence

CVE-2025-10609: Logo Software TigerWings ERP hard-coded credentials

CVE-2025-10609 · Severity: medium · CVSS 5.9 · Published 2025-10-03

Vendors: Logo Software, Logo Software Inc..

Executive brief

Logo Software Inc. TigerWings ERP, a business management software suite, contains a security flaw where sensitive login information or encryption keys are permanently written into the software's code. An individual with physical access to the system could extract these secrets to bypass security controls or tamper with the application's integrity. This could lead to unauthorized changes in business data or a disruption of ERP services.

Technical details

A Use of Hard-coded Credentials vulnerability (CWE-798) exists in Logo Software Inc. TigerWings ERP versions 01.01.00 through 3.03.00. The vulnerability stems from sensitive constants, such as credentials or cryptographic keys, being embedded directly within the application's executable files. An attacker with physical access and low-level user privileges can read these constants from the binary. According to the CVSS vector, this can be leveraged to impact the integrity of the system. Users are advised to update to version 3.03.00 or later to mitigate this risk.

Affected products

  • Logo Software Inc. TigerWings ERP 01.01.00 to 3.03.00

Timeline

  • 2025-10-03: disclosed
  • 2025-10-03: advisory

References