Executive brief
A critical security flaw has been identified in the Vimesoft Enterprise Video Platform, a system used by organizations to manage and stream corporate video content. This vulnerability allows an unauthorized person to change user passwords without proper verification, effectively letting them take over any account on the system. This could lead to the theft of sensitive corporate data, unauthorized access to private video archives, and a total loss of control over the platform.
Technical details
The Vimesoft Enterprise Video Platform is vulnerable to an unverified password change (CWE-620), which facilitates a complete authentication bypass. The flaw exists in the password management component where the system fails to adequately verify the identity or current credentials of a user before processing a password change request. An unauthenticated remote attacker can exploit this over the network with no user interaction required. By successfully exploiting this vulnerability, an attacker can reset administrative or user passwords to gain full access to the platform. The issue is addressed in version 3.25.0.
Affected products
- Vimesoft Inc. Enterprise Video Platform 3.11.0.0 to 3.25.0
Timeline
- 2026-07-17: advisory: Initial disclosure by TR-CERT
- 2026-07-17: disclosed: NVD publication date