---
id: CVE-2025-10644
title: >-
  Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication
  Bypass Vulnerability
summary: >-
  Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication
  Bypass Vulnerability. This vulnerability allows remote attackers to bypass
  authentication on Wondershare Repairit. Authentication is not required to
  exploit th…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-266
vendor: wondershare
product: repairit
affected:
  - repairit = 6.5.2
published: '2025-09-17'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10644'
references:
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-25-896/'
    label: zdi-disclosures@trendmicro.com
tags:
  - nvd
epss: 0.02996
epssPercentile: 0.8681
zeroDay: true
ingestedAt: '2026-09-26T00:22:39.936Z'
---

## Overview

Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the permissions granted to an SAS token. An attacker can leverage this vulnerability to launch a supply-chain attack and execute arbitrary code on customers' endpoints. Was ZDI-CAN-26892.

## Affected

- `repairit = 6.5.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
