VORANT. Threat Intelligence Sign in Get the full feed

CGM CLININET flaws allow full auth bypass

medium vulnerability healthcare

CERT Polska coordinated disclosure of 8 vulnerabilities in CGM CLININET and CGM NETRAAD healthcare software, including a critical authentication bypass and multiple injection flaws.

CERT Polska has published details on eight vulnerabilities affecting CGM CLININET and CGM NETRAAD, healthcare information and PACS systems used to manage patient data. The most severe issue, CVE-2025-30035, allows an attacker to fully bypass authentication and take over any active user session by supplying only a username, without needing a password or other credentials. A related flaw, CVE-2025-30042, undermines smart-card authentication because verification relies solely on a certificate number checked locally on the client, meaning possession of the certificate number alone is sufficient to authenticate.

Several injection vulnerabilities were also disclosed: CVE-2025-10350 is a SQL injection in the NETRAAD imageserver module reachable via PACS C-FIND queries, potentially exposing data shared with CLININET; CVE-2025-30044 covers unsanitized parameters in multiple CGI utility scripts enabling code injection; and CVE-2025-30062 is a SQL injection in the validateOrgUnit function of the CheckUnitCodeAndKey.pl service. An insecure direct object reference (CVE-2025-58402) allows access to other users' messages and attachments via sequential MessageID manipulation, while CVE-2025-58405 and CVE-2025-58406 describe missing clickjacking protections and absent security headers, exposing users to client-side attacks.

These vulnerabilities were reported through CERT Polska's coordinated vulnerability disclosure process, largely credited to researcher Maciej Kazulak. No evidence of active exploitation is mentioned; the advisory is a responsible-disclosure notice affecting the healthcare sector, and organizations running affected CGM CLININET or CGM NETRAAD versions (NETRAAD imageserver before 7.9.0) should apply vendor patches promptly given the sensitivity of medical record systems.

Mentioned in this report

Vulnerabilities CVE-2025-10350CVE-2025-30035CVE-2025-30042CVE-2025-30044CVE-2025-30062CVE-2025-58402CVE-2025-58405CVE-2025-58406

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-10350

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free