PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-7706 TUBITAK BILGEM Software Technologies Research Institute CVE debrief

A Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion. This issue affects Liderahenk: from 3.0.0 to 3.3.1 before 3.5.0. The CVSS score for this vulnerability is 6.1, with a severity rating of MEDIUM.

Vendor
TUBITAK BILGEM Software Technologies Research Institute
Product
Liderahenk
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-17
Original CVE updated
2026-06-05
Advisory published
2026-02-17
Advisory updated
2026-06-05

Who should care

Users of Liderahenk versions from 3.0.0 to 3.3.1 should apply the patch or upgrade to version 3.5.0 or later.

Technical summary

The vulnerability is caused by a missing authentication mechanism for a critical function in Liderahenk, allowing for Remote Code Inclusion. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply the patch or upgrade to Liderahenk version 3.5.0 or later.
  • Review and implement additional security measures to prevent Remote Code Inclusion attacks.

Evidence notes

The CVE record and NVD detail can be found at [cve-org] and [nvd], respectively. Additional information can be found at [ref-4] and [ref-5].

Official resources

CVE-2025-7706 was published on [cvePublishedAt] and modified on [cveModifiedAt].