MFlash Remote Code Execution (RCE) after authentication of a user with the "administrator" role
Vulnerability Description
A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9060
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- The vulnerability was discovered by Marsel Shagiev and Evgeny Velikoivanenko from Kaspersky (https://kaspersky.com)
Affected Vendor
MSoft
View all reports →