PT-2025-39391 · Unknown · Imonitor Eam
CVE-2025-10542
·
Publicado
2025-09-25
·
Atualizado
2025-09-25
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iMonitor EAM version 9.6394
Description
The software ships with default administrative credentials that are displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This allows reading sensitive telemetry, including keylogger output, and issuing arbitrary actions to all connected clients.
Recommendations
Change the default administrative credentials.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Imonitor Eam