VYPR
Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026

Weak password hashing in R-SOFT DMS

CVE-2026-41879

Description

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.

This issue was fixed in version v3.17-2000.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.