CVE-2025-12480

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

  • Published Nov 10, 2025
  • CVSS 9.1 critical
  • 95.4% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available
  • A fix is available

Affected software

In the news

CVE-2025-12480 at the National Vulnerability Database