CVE-2025-26318

hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.
Configurations

No configuration.

History

03 Apr 2025, 14:15

Type Values Removed Values Added
CWE CWE-281

20 Mar 2025, 14:15

Type Values Removed Values Added
Summary (en) Insecure permissions in TSplus Remote Access v17.30 allow attackers to retrieve a list of all domain accounts currently connected to the application. (en) hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.
CWE CWE-201
CVSS v2 : unknown
v3 : 9.4
v2 : unknown
v3 : 5.8

05 Mar 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.4
CWE CWE-281
References () https://github.com/Frozenka/CVE-2025-26318 - () https://github.com/Frozenka/CVE-2025-26318 -
Summary
  • (es) Los permisos inseguros en TSplus Remote Access v17.30 permiten a los atacantes recuperar una lista de todas las cuentas de dominio actualmente conectadas a la aplicación.

04 Mar 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 21:15

Updated : 2025-04-03 14:15


NVD link : CVE-2025-26318

Mitre link : CVE-2025-26318

CVE.ORG link : CVE-2025-26318


JSON object : View

Products Affected

No product.

CWE
CWE-201

Insertion of Sensitive Information Into Sent Data