← Back to browse · API

CVE-2022-25246

Severity
CRITICAL
CVSS
9.8
EPSS
0.01807
Risk score
39.83
CISA KEV
No
PoC
No
Published
2022-03-16
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2022-29943, GHSA-R24P-MXFV-R3VM
Products
PTC:Axeda Desktop Server for Windows All Versions, PTC:Axeda agent All Versions
Sources
euvd EUVD-2022-29943

Description

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system.

References