CRITICAL
CVE-2025-12480
CVSS
9.1
KEV
Description
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
Summary dbcve.org
Triofox versions prior to 16.7.10368.56560 contain an Improper Access Control vulnerability that allows unauthorized access to initial setup pages even after the product setup has been completed. This is a critical security flaw as setup pages typically expose privileged configuration functions and should not be accessible post-setup.
Mitigation
Upgrade Triofox to version 16.7.10368.56560 or later to remediate the improper access control vulnerability.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
90.53%
Probability of exploitation in next 30 days
99.8th percentile
References
https://access.triofox.com/releases_history/
Release Notes
https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480
Exploit, Third Party Advisory
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md
Third Party Advisory
https://www.triofox.com/
Product
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.