Junglewise Threat Intelligence

CVE-2025-4320: Birebirsoft Sufirmam authentication bypass in password recovery

CVE-2025-4320 · Severity: critical · CVSS 10 · Published 2026-01-23

Executive brief

A critical security flaw has been identified in Birebirsoft Sufirmam software involving a weak password recovery process. This vulnerability allows an unauthorized person to bypass security controls and gain full access to user accounts without needing a password. An exploit could lead to a total compromise of the system, including the theft of sensitive data and disruption of business operations.

Technical details

Birebirsoft Sufirmam is vulnerable to an authentication bypass (CWE-305) rooted in a weak password recovery mechanism (CWE-640). The flaw allows a remote, unauthenticated attacker to exploit the 'forgot password' functionality to reset or bypass authentication requirements. Because the vulnerability is network-accessible and requires no user interaction or prior privileges, it has been assigned a CVSS score of 10.0. As of the disclosure date, the vendor has not responded to reports, and no official patch has been confirmed.

Affected products

  • Birebirsoft Software and Technology Solutions Sufirmam through 23012026

Timeline

  • 2026-01-23: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2026-01-23: advisory: CVE-2025-4320 published

References

Related threats