Executive brief
Liderahenk, a central management system for corporate IT infrastructure, contains a security flaw where critical functions do not require proper identity verification. This allows an attacker to potentially take control of the system, execute unauthorized commands, or abuse administrative privileges. Such an exploit could lead to a total compromise of the managed network, data theft, or significant operational disruption.
Technical details
A Missing Authentication for Critical Function vulnerability (CWE-306) exists in TUBITAK BILGEM Liderahenk versions prior to 3.5.1. The flaw allows unauthenticated attackers to access sensitive functions, leading to Remote Code Inclusion (RCI), command injection, and privilege abuse. While the attack vector is network-based, the CVSS vector indicates high complexity and requires user interaction. Successful exploitation enables full system compromise. Users are advised to upgrade to version 3.5.1 or later to remediate the issue.
Affected products
- TUBITAK BILGEM Software Technologies Research Institute Liderahenk before 3.5.1
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory