CVE-2025-7706
Improper Access Control in TUBITAK BILGEM's Liderahenk
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion.
This issue affects Liderahenk: from 3.0.0 to 3.3.1 before 3.5.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Affected products
TUBITAK BILGEM Software Technologies Research Institute · LiderahenkWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →