CVE-2025-53704
Last modified
CVE-2025-53704 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-53704?
How severe is CVE-2025-53704?
How do I fix CVE-2025-53704?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53695OS Command Injection in iSTAR Ultra products web application…9.4
- CVE-2025-53696iSTAR Ultra performs a firmware verification on boot, howeve…9.3
- CVE-2025-5370A vulnerability classified as critical was found in PHPGuruk…9.8
- CVE-2025-53701Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS …6.1
- CVE-2025-53702Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of…6.5
- CVE-2025-53703DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data w…8.7
- CVE-2025-53705In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt S…8.4
- CVE-2025-53706Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-53707A reflected cross-site scripting (xss) vulnerability exists …6.1
- CVE-2025-53709Secure-upload is a data submission service that validates si…5.4
- CVE-2025-5371A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-53710Due to a product misconfiguration in certain deployment type…7.5
Are you affected by CVE-2025-53704?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
