CVE-2026-25608: Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy Ster

Low severity, CVSS 2.3. EPSS: 0.3% chance of exploitation in the next 30 days.

STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5.

Affected products

Published 2026-05-22. Last modified 2026-07-23.