Smarttfoxx/CVE-2025-60791
PoC files
1 fileFile viewing is interactive and short-lived. Downloads are password-protected ZIP archives using password eip.
Analysis
Technical assessment
The artifact is a README file that describes CVE-2025-60791, a cleartext storage of sensitive information vulnerability in Easywork Enterprise 2.1.3.354. It explains that valid license keys remain in process memory after a failed activation and can be extracted via debugging or memory dump analysis. The file contains no executable code, only a textual description and two embedded screenshots.
Backdoor review
No backdoor observed in reviewed code
The artifact contains only a README.md file describing CVE-2025-60791 and displaying two embedded images. No executable code, scripts, commands, or deceptive payloads are present in the reviewed text. The content is purely informational documentation of a known vulnerability.
Classification basis and observed behavior
Classification basis
The artifact is a README file that provides a textual description of the CVE-2025-60791 vulnerability and its exploitation method, but it does not contain any executable code, scripts, or tools to perform the exploitation or scanning. It is a technical writeup.
README.md:1-10Requirements
- Attach a debugger or analyze a process/memory dump of Easywork Enterprise after a failed activation attempt.
README.md:4
Observed behavior
- The artifact describes that valid device-bound license keys are left in cleartext in process memory after a failed activation attempt.
README.md:4 - The artifact includes two screenshots, but their content is not provided as text evidence.
README.md:6-8
Behaviors behind the backdoor verdict
Observables
- Vulnerability Description
- CVE-2025-60791: Cleartext Storage of Sensitive Information in Memory in Easywork Enterprise 2.1.3.354The README describes the vulnerability and its impact, consistent with the associated CVE record.
README.md:2-4 - Embedded Image
- https://github.com/user-attachments/assets/2d02779e-6810-46ec-9e8e-fb09d155055aImage likely shows a screenshot related to the vulnerability; no executable content is present in the text.
README.md:6 - Embedded Image
- https://github.com/user-attachments/assets/6aaeb592-8c21-4197-afa4-8f860a91fd9eImage likely shows a screenshot related to the vulnerability; no executable content is present in the text.
README.md:8
What the analysis did not establish
- The artifact contains two embedded screenshots (lines 6 and 8) whose content is not provided as text and therefore could not be analyzed.
- The analysis is based solely on the supplied text of the README file; no other files from the repository were provided.
- Only the README.md file was reviewed; the repository may contain other files not included in the evidence packet.
- The content of the embedded images was not inspected; they could contain text or instructions, but no executable code.
This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.