CVE-2025-10644Critical· 9.4▾ Hadal0dayWondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit th…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 51.7 · likelihood 0.6 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.0%
Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the permissions granted to an SAS token. An attacker can leverage this vulnerability to launch a supply-chain attack and execute arbitrary code on customers' endpoints. Was ZDI-CAN-26892.
repairit = 6.5.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10643Critical· 9.1Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability
CVE-2021-44596Critical· 9.8Wondershare LTD Dr
CVE-2021-44595High· 8.8Wondershare Dr
CVE-2025-66296High· 8.8Grav is a file-based Web platform
CVE-2025-13806High· 7.3A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT
CVE-2025-10608Medium· 6.3A vulnerability was detected in Portabilis i-Educar up to 2.10