CVE-2025-59745 MEDIUM

CVE-2025-59745: Multiple vulnerabilities in AndSoft's e-TMS

Vendor Andsoft
Product e-TMS
Weakness CWE-327 · Broken crypto
Published October 2, 2025
Last update October 2, 2025

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cryptographically vulnerable hash algorithm and is no longer considered secure for storing or transmitting passwords. It is vulnerable to collision attacks and can be easily cracked with modern hardware, exposing user credentials to potential risks.

Key dates

02Disclosure timeline

October 2, 2025 CVE published
October 2, 2025 Record updated