CVE-2026-25608: Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy Ster
Low severity, CVSS 2.3. EPSS: 0.3% chance of exploitation in the next 30 days.
STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5.
Affected products
- Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy Ster: before 9.5 (fixed in 9.5)
Published 2026-05-22. Last modified 2026-07-23.