Record summary

CVE-2025-53118 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 10, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

VulnCheck, CVE List9.0.* to ≤ 11.3.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALSecurden Unified PAM - Authentication Bypass

An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.

Impact

Unauthenticated attackers can control administrator backup functions to compromise passwords, secrets, and application session tokens stored in Unified PAM.

Remediation

Upgrade Securden Unified PAM to the latest version that implements proper authentication checks on backup functions.

AuthorsDhiyaneshDk, pussycat0x, iamnoooob, pdresearch
Template tagscvecve2025securdenpamauth-bypassvulnvkev
FOFA: (icon_hash="1798893256" || icon_hash="-766529773")

Source: ProjectDiscovery

References

2