Junglewise Threat Intelligence

CVE-2025-7355: Beefull Energy Technologies Beefull App authorization bypass

CVE-2025-7355 · Severity: medium · CVSS 6.5 · Published 2025-09-16

Executive brief

Beefull Energy Technologies Beefull App, a mobile application used for managing energy services and power bank rentals, contains a security flaw that allows users to bypass authorization checks. By manipulating specific identifiers within the app, an attacker could gain unauthorized access to data belonging to other users. This could lead to the exposure of sensitive customer information and potentially disrupt service operations.

Technical details

The Beefull App is vulnerable to an Insecure Direct Object Reference (IDOR) flaw, specifically categorized as CWE-639 (Authorization Bypass Through User-Controlled Key). The vulnerability exists because the application fails to properly validate that a user has the authority to access a resource identified by a user-provided key or identifier. A remote attacker with low-level authenticated access can manipulate these identifiers in network requests to access sensitive information belonging to other users. The issue is resolved in versions released after July 24, 2025.

Affected products

  • Beefull Energy Technologies Beefull App before 24.07.2025

Timeline

  • 2025-09-16: disclosed
  • 2025-09-16: advisory
  • 2025-07-24: patched: Versions before this date are affected.

References