Back to overview

CVE-2025-10542

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This enables reading highly sensitive telemetry (including keylogger output) and issuing arbitrary actions to all connected clients.

Metadata

CVE ID
CVE-2025-10542
State
PUBLISHED
Assigner
SEC-VLab
Reserved
2025-09-16 07:44 UTC
Published
2025-09-25 14:35 UTC
Last updated
2025-11-03 18:08 UTC
Primary CWE
CWE-1392
CWE-1392 Use of Default Credentials
Vendor / Product
iMonitor Software Inc. / iMonitor EAM
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
iMonitor Software Inc. iMonitor EAM 9.63.94
Weakness (CWE)
CWESourceDescription
CWE-1392 cna CWE-1392 Use of Default Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview