SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-50325

MEDIUM · CVSS 5.4 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

BandiZip version 7.37 is vulnerable to an authentication bypass that enables remote attackers to circumvent the Mark-of-the-Web protection mechanism. This flaw could lead to unauthorized access to potentially harmful content, posing a risk to users who rely on this software for secure file management. Organizations using BandiZip should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-50325
Severity
MEDIUM
CVSS
5.4
EPSS
0.29%

Original NVD Description

BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip