CERT Polska disclosed three vulnerabilities in STER software
CERT Polska disclosed three vulnerabilities in STER software: SQL injection (CVE-2026-25606), weak password encoding (CVE-2026-25607), and cleartext transmission (CVE-2026-25608), all fixed in version 9.5.
CERT Polska coordinated the disclosure of three security vulnerabilities affecting STER software, reported by Michelin CERT. The most critical issue is CVE-2026-25606, a SQL injection vulnerability in multiple search filters that allows authenticated attackers to access sensitive data belonging to other users or any data accessible by the application. The second vulnerability, CVE-2026-25607, involves the use of a weak password encoding algorithm that enables attackers to reverse-engineer passwords by analyzing encoded values. The third issue, CVE-2026-25608, exposes users to man-in-the-middle attacks due to unencrypted TCP traffic transmission, potentially compromising passwords, personal data, and authentication tokens.
All three vulnerabilities have been addressed in STER version 9.5. Organizations using earlier versions should prioritize upgrading to mitigate these risks. The combination of SQL injection with weak password encoding and cleartext transmission creates a significant attack surface for both authenticated and network-adjacent attackers.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-25606
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free