← Back to browse · API

CVE-2025-0994

Severity
HIGH
CVSS
8.6
EPSS
0.31309
Risk score
70.36
CISA KEV
Yes
PoC
No
Published
2025-02-06
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2025-1955, GHSA-M5Q8-8X36-W25P
Products
Trimble:Cityworks, Trimble:Cityworks (with office companion) 0 <23.10, Trimble:Cityworks 0 <15.8.9
Sources
euvd EUVD-2025-1955
cisa.gov CVE-2025-0994

Description

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

References