CVE-2025-3920 - CVE House
Back to Database
Status published High CVE-2025-3920

Hard-coded Password in SUR-FBD CMMS

Vulnerability Description

A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the system or the application's installation directory could extract these credentials, potentially leading to a complete compromise of the application's administrative functions. This issue was fixed in version 2025.03.27 of the SUR-FBD CMMS software.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3920

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Thomas Hayen (Easi)

Affected Vendor

SUR-FBD CMMS

View all reports →

Affected Software

SUR-FBD CMMS
Vulnerable Versions:
0

Timeline

Official Publish: July 7th, 2025
Last Modified: July 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)