CVE-2025-10548
Last modified
CVE-2025-10548 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installer downloads and executes external components using curl.exe --insecure, enabling a man-in-the-middle attacker to deliver malicious files that are executed with SYSTEM privileges. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installer downloads and executes external components using curl.exe --insecure, enabling a man-in-the-middle attacker to deliver malicious files that are executed with SYSTEM privileges. This can lead to full remote code execution with administrative rights. No patch is available as the vendor has been unresponsive. It is assumed that previous versions are also affected, but this is not confirmed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-10548?
How severe is CVE-2025-10548?
How do I fix CVE-2025-10548?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-10542iMonitor EAM 9.6394 ships with default administrative creden…9.8
- CVE-2025-10543In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) vers…5.3
- CVE-2025-10544Unrestricted file upload vulnerability in DocAve 6.13.2, Per…8.6
- CVE-2025-10545Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fa…4.3
- CVE-2025-10546This vulnerability exist in PPC 2K15X Router, due to imprope…5.1
- CVE-2025-10547An uninitialized variable in the HTTP CGI request arguments …9.8
- CVE-2025-10549EfficientLab Controlio before v1.3.95 contains a DLL hijacki…5.1
- CVE-2025-1055A vulnerability in the K7RKScan.sys driver, part of the K7 S…5.6
- CVE-2025-10551A Stored Cross-site Scripting (XSS) vulnerability affecting …5.4
- CVE-2025-10552A stored Cross-site Scripting (XSS) vulnerability affecting …6.1
- CVE-2025-10553A Stored Cross-site Scripting (XSS) vulnerability affecting …5.4
- CVE-2025-10554A stored Cross-site Scripting (XSS) vulnerability affecting …5.4
Are you affected by CVE-2025-10548?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
