PT-2026-4740 · Unknown · Exos 9300 Server

CVE-2025-59090

·

Publicado

2026-01-26

·

Atualizado

2026-01-27

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions exos 9300 server (affected versions not specified)
Description A SOAP API is reachable on port 8002 on the exos 9300 server without requiring authentication. Network access to the server allows for actions such as creating arbitrary access log events and querying two-factor authentication (2FA) PINs associated with enrolled chip cards. The API endpoint is ''/'' on port 8002.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-59090

Produtos afetados

Exos 9300 Server