216.73.217.24

CVE-2025-10539

· Published 28/04/2026 09:16 · Modified 29/04/2026 20:16

Labels: CVE-2025-10539 2026-04-28551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2025-10539CWE-295

Essential information

Published
28/04/2026 09:16
Modified
29/04/2026 20:16
Author
Creator
CVSS
4.8 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
desktime / desktime time tracking app cpe:2.3:a:desktime:desktime_time_tracking_app:<1.3.674:*:*:*:*:*:*:*

References