Home

Description

OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.

PUBLISHED Reserved 2025-10-16 | Published 2025-10-16 | Updated 2025-10-17 | Assigner cisa-cg




HIGH: 8.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Red
CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unknown

11.1.0 before 11.13.2.0
affected

11.13.2.0
unaffected

Credits

Matthew Zamat, CISA

References

docs.opexustech.com/...OIAXpress_Release_Notes_11.13.2.0.pdf (url)

raw.githubusercontent.com/...IT/white/2025/va-25-289-01.json (url)

www.cve.org/CVERecord?id=CVE-2025-62586 (url)

cve.org (CVE-2025-62586)

nvd.nist.gov (CVE-2025-62586)

Download JSON