CVE-2025-10539
Last modified
CVE-2025-10539 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Draugiemgroup | Desktime Time Tracking | < 1.3.674 |
References
- https://r.sec-consult.com/desktimeThird Party Advisory
- http://seclists.org/fulldisclosure/2026/Apr/20Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2026/Apr/21Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-10539?
How severe is CVE-2025-10539?
How do I fix CVE-2025-10539?
Are you affected by CVE-2025-10539?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
