CVE-2025-53118
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
9.8
CVSS
30.5%
EPSS (exploit prob.)
98th
EPSS percentile
2025-08-25
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-53118