{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-12480/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-12480/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-12480/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-12480/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-12480/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-12480"},"sightings":{"href":"/api/v1/sightings/cve-2025-12480"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-12480.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-12480\n\ninfo:\n  name: Triofox - Improper Access Control\n  author: johnk3r,gti\n  severity: critical\n  description: |\n    The Gladinet Triofox solution before 12.91.1126.65588 and CentreStack before 12.10.595.65696 allow unauthenticated access to the /management/admindatabase.aspx endpoint, exposing sensitive database management functionality to anyone with network access. An unauthenticated attacker can remotely access, view, and potentially interact with the database management interface, risking data disclosure or system compromise.\n  impact: |\n    Attackers may gain access to sensitive administrative functions of the Triofox database, resulting in unauthorized data access, modification, or potential system compromise.\n  remediation: |\n    Upgrade to Triofox 12.91.1126.65588 or CentreStack 12.10.595.65696 and later to resolve this vulnerability and restrict unauthenticated access to the administrative database panel.\n  reference:\n    - https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480\n    - https://attackerkb.com/topics/5C4wRy6hY7/cve-2025-12480/rapid7-analysis\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-12480\n  classification:\n    cve-id: CVE-2025-12480\n    epss-score: 0.90532\n    epss-percentile: 0.99797\n    cwe-id: CWE-306\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n  metadata:\n    verified: true\n    max-request: 1\n    shodan-query: http.favicon.hash:-177043778\n    fofa-query: icon_hash=\"-177043778\"\n  tags: cve,cve2025,triofox,unauth,exposure,vkev,kev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /management/admindatabase.aspx HTTP/1.1\n        Host: localhost\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - 'Triofox Enterprise'\n          - 'Manage Database'\n          - 'Configure Database'\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 490a00463044022001a09e62fef9e5c9645dba679d09b0df8cb8eecf774e9aa2c4a7a121a5976243022059a3ea99f84731716db0f0e0a88ec0bd8d158bfce99f875a33fe381d7f760a14:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2025-12480"}