Back to overview

CVE-2025-10640

CRITICAL
9.8
CVSS 3.1
Description
An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side authentication checks to bypass the login prompt in the WorkExaminer Professional console to gain administrative access to the WorkExaminer server and therefore all sensitive monitoring data. This includes monitored screenshots and keystrokes of all users. The WorkExaminer Professional console is used for administrative access to the server. Before access to the console is granted administrators must login. Internally, a custom protocol is used to call a respective stored procedure on the MSSQL database. The return value of the call is not validated on the server-side. Instead it is only validated client-side which allows to bypass authentication.

Metadata

CVE ID
CVE-2025-10640
State
PUBLISHED
Assigner
SEC-VLab
Reserved
2025-09-17 14:05 UTC
Published
2025-10-21 11:43 UTC
Last updated
2025-11-03 17:31 UTC
Primary CWE
CWE-602
CWE-602 Client-Side Enforcement of Server-Side Security
Vendor / Product
EfficientLab / WorkExaminer Professional
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
EfficientLab WorkExaminer Professional <= 4.0.0.52001
Weakness (CWE)
CWESourceDescription
CWE-602 cna CWE-602 Client-Side Enforcement of Server-Side Security
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview