#WorkExaminer
SEC Consult SA-20251021-0 :: Multiple Vulnerabilities in EfficientLab WorkExaminer Professional (CVE-2025-10639, CVE-2025-10640, CVE-2025-10641)

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 21SEC Consult Vulnerability Lab Security Advisory < 20251021-0 >
==…

#hackernews #news
SEC Consult SA-20251021-0 :: Multiple Vulnerabilities in EfficientLab WorkExaminer Professional (CVE-2025-10639, CVE-2025-10640, CVE-2025-10641)
Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 21SEC Consult Vulnerability Lab Security Advisory < 20251021-0 > ======================================================================= title: Multiple Vulnerabilities product: EfficientLab WorkExaminer Professional vulnerable version: <= 4.0.0.52001 fixed version: - CVE number: CVE-2025-10639, CVE-2025-10640, CVE-2025-10641 impact: Critical homepage:...
seclists.org
October 22, 2025 at 5:59 PM
CVE-2025-10640 - Missing Server-Side Authentication Checks in EfficientLab WorkExaminer Professional
CVE ID : CVE-2025-10640

Published : Oct. 21, 2025, 12:15 p.m. | 26 minutes ago

Description : An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer...
CVE-2025-10640 - Missing Server-Side Authentication Checks in EfficientLab WorkExaminer Professional
An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side authentication checks to bypass the login prompt in the WorkExaminer Professional console to gain administrative access to the WorkExaminer server and therefore all sensitive monitoring data. This includes monitored screenshots and keystrokes of …
cvefeed.io
October 21, 2025 at 1:08 PM
CVE-2025-10641 - Unencrypted cleartext communication in EfficientLab WorkExaminer Professional
CVE ID : CVE-2025-10641

Published : Oct. 21, 2025, 12:15 p.m. | 26 minutes ago

Description : All WorkExaminer Professional traffic between monitoring client, console and server...
CVE-2025-10641 - Unencrypted cleartext communication in EfficientLab WorkExaminer Professional
All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the transmitted sensitive data. An attacker can also freely modify the data on the wire. The monitoring clients transmit their data to the server …
cvefeed.io
October 21, 2025 at 12:58 PM
CVE-2025-10639 - Usage of Hardcoded FTP Credentials EfficientLab WorkExaminer Professional
CVE ID : CVE-2025-10639

Published : Oct. 21, 2025, 12:15 p.m. | 26 minutes ago

Description : The WorkExaminer Professional server installation comes with an FTP server that is used...
CVE-2025-10639 - Usage of Hardcoded FTP Credentials EfficientLab WorkExaminer Professional
The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain …
cvefeed.io
October 21, 2025 at 12:53 PM