Executive brief
Optimus Software Brokerage Automation, a platform used for managing financial brokerage operations, contains multiple security flaws in its authentication and password recovery systems. These vulnerabilities allow an attacker to bypass security checks, potentially gaining unauthorized access to sensitive financial data or administrative functions. An exploit could lead to the theft of customer information, unauthorized transactions, or the manipulation of critical business records.
Technical details
Optimus Software Brokerage Automation versions prior to 1.1.71 are affected by multiple authentication-related vulnerabilities, including CWE-639 (Authorization Bypass Through User-Controlled Key), CWE-640 (Weak Password Recovery Mechanism), and CWE-302 (Authentication Bypass by Assumed-Immutable Data). The root cause involves the application trusting client-side data that should be immutable and failing to properly validate user-controlled keys during authorization checks. A remote attacker with low privileges can exploit these flaws over the network to bypass authentication, manipulate registry information, and gain unauthorized access to data. The vulnerabilities are addressed in version 1.1.71.
Affected products
- Optimus Software Brokerage Automation before 1.1.71
Timeline
- 2025-11-14: advisory: Initial publication of CVE-2025-8855