CVE-2025-2395: Edetw U-Office Force

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.

Affected products

  • Edetw U-Office Force: before 28.0 (fixed in 28.0)

Published 2025-03-17. Last modified 2026-06-17.