216.73.217.22

CVE-2025-12480

· Published 12/11/2025 01:00 · Modified 21/12/2025 19:22 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2025-12480 2025-11-10CVE-2025-12480CWE-284[email protected]

Essential information

Published
12/11/2025 01:00
Modified
21/12/2025 19:22
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:N

CVSS metrics

Description

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gladinet / triofox cpe:2.3:a:gladinet:triofox:*:*:*:*:*:*:*:*

References