CVE-2025-10542

CRITICAL

iMonitor EAM 9.6394 - Auth Bypass

Title source: llm
STIX 2.1

Description

iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This enables reading highly sensitive telemetry (including keylogger output) and issuing arbitrary actions to all connected clients.

Scores

CVSS v3 9.8
EPSS 0.0018
EPSS Percentile 39.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-1392
Status published
Products (1)
iMonitor Software Inc./iMonitor EAM 9.63.94
Published Sep 25, 2025
Tracked Since Feb 18, 2026