The following table lists the changes that have been made to the
CVE-2025-9060 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Aug. 15, 2025
Action Type Old Value New Value Added Description A vulnerability has been found in the MSoft MFlash application that allows
execution of arbitrary code on the server. The issue occurs in the
integration configuration functionality that is only available to
MFlashadministrators. The vulnerability is related to insufficient validation
of parameters when setting up security components.This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Added CWE CWE-20 Added Reference https://github.com/klsecservices/Advisories/blob/master/K-MSoft-2025-002.md