CVE-2025-9060 - CVE House
Back to Database
Status published Critical CVE-2025-9060

MFlash Remote Code Execution (RCE) after authentication of a user with the "administrator" role

Vulnerability Description

A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9060

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • The vulnerability was discovered by Marsel Shagiev and Evgeny Velikoivanenko from Kaspersky (https://kaspersky.com)

Affected Vendor

Affected Software

MFlash
Vulnerable Versions:
8.0

Timeline

Official Publish: August 15th, 2025
Last Modified: August 15th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)