Junglewise Threat Intelligence

CVE-2025-2417: Akinsoft e-Mutabakat authentication bypass via brute force

CVE-2025-2417 · Severity: high · CVSS 8.6 · Published 2025-09-04

Vendors: AKINSOFT.

Executive brief

Akinsoft e-Mutabakat, a financial reconciliation software, contains a security flaw that fails to limit repeated login attempts. This allows an attacker to potentially bypass authentication through brute-force methods, leading to unauthorized access to sensitive financial data and business records. Such an incident could result in data theft, financial fraud, or disruption of corporate reconciliation processes.

Technical details

The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the Akinsoft e-Mutabakat application. The root cause is a lack of rate-limiting or account lockout mechanisms on the authentication interface. A remote, unauthenticated attacker can exploit this by launching automated brute-force or credential stuffing attacks over the network. Successful exploitation allows the attacker to bypass authentication and gain unauthorized access to the system. The issue is reported to affect version 2.02.06.

Affected products

  • Akinsoft e-Mutabakat 2.02.06

Timeline

  • 2025-09-04: disclosed
  • 2025-09-04: advisory

References

Related threats