# STER software patches three vulnerabilities

Published: 2026-05-22 · Severity: medium
Canonical: https://vorant.io/reports/d73b1f89-cdf4-53f8-95a7-5092e36763e3/ster-software-patches-three-vulnerabilities

> STER software had a SQL injection, weak password encoding, and unencrypted TCP traffic flaws, all fixed in version 9.5.

CERT Polska coordinated disclosure of three vulnerabilities in STER software, reported by Michelin CERT. CVE-2026-25606 is a SQL injection vulnerability in the application's Search Filters that allows an authenticated attacker to access sensitive data belonging to other users or any data the application can reach. CVE-2026-25607 involves use of a weak password encoding algorithm, which could allow an attacker to derive password values by analyzing how known passwords are encoded. CVE-2026-25608 stems from STER's use of unencrypted TCP traffic to transmit data, exposing passwords, personal data, and authentication tokens to Man-in-the-Middle attacks.

All three issues were addressed in STER version 9.5. There is no indication in the advisory of active exploitation in the wild; this is a standard responsible disclosure and patch notice rather than evidence of an ongoing attack campaign.

## Mentioned in this report

- Vulnerabilities: CVE-2026-25606, CVE-2026-25607, CVE-2026-25608

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-25606

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d73b1f89-cdf4-53f8-95a7-5092e36763e3/ster-software-patches-three-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
