CVE-2025-6512 describes a critical vulnerability where a non-admin user can embed malicious scripts into reports on a client, which are then executed with administrator privileges on the BRAIN2 server. This network-exploitable flaw has a CVSS score of 10.0, indicating a complete compromise of confidentiality, integrity, and availability. While no specific products are listed, the vulnerability's nature suggests a significant risk to affected BRAIN2 server environments. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bizerba SE & Co. KG | BRAIN2 | >= 0.0, < 3.06CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.