Cyber News / Article / Vulnerabilities in STER software

Vulnerabilities in STER software
CERT Polska has received a report about vulnerabilities in STER software and participated in coordination of their disclosure.
The vulnerabilityCVE-2026-25606: A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated attacker to view sensitive data such as data belonging to other users, or any other data that the application itself is able to access
The vulnerabilityCVE-2026-25607: Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.
The vulnerabilityCVE-2026-25608: STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens.
These issues were fixed in version 9.5.
We thank Michelin CERT for the responsible vulnerability report.
Related articles
Android’s September 2026 Updates Patch 180 Vulnerabilities
1 day ago
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
1 day ago
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
3 days ago
You might Also like

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

