CVE-2025-27007 is a critical Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers (versions up to 1.0.82) that allows for Privilege Escalation. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication, enabling attackers to gain full control over affected systems. Active exploitation has been observed, with readily available exploit modules in Metasploit and Nuclei, and public proof-of-concept code on ExploitDB. The vulnerability has garnered significant community attention and media coverage, indicating widespread awareness and potential for further attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Brainstorm Force | OttoKit | >= 0, <= 1.0.82CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.