CVE-2025-3709: Flowring Technology Agentflow - Account Lockout Bypass

9.8 CVSS

Description

Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.

Classification

CVE ID: CVE-2025-3709

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem Types

CWE-307 Improper Restriction of Excessive Authentication Attempts

Affected Products

Vendor: Flowring Technology

Product: Agentflow

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.75% (scored less or equal to compared to others)

EPSS Date: 2025-05-04 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-3709
https://www.twcert.org.tw/tw/cp-132-10091-12462-1.html
https://www.twcert.org.tw/en/cp-139-10090-112f7-2.html

Timeline