CVE-2025-12871: Aenrich A+hrd

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.

Affected products

  • Aenrich A+hrd: up to and including 7.5

Published 2025-11-12. Last modified 2026-06-17.