CVE-2025-53704

HIGH

Pivot Client - Privilege Escalation

Title source: llm
STIX 2.1

Description

The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (2)
MAXHUB/Pivot client application < 1.36.2
MAXHUB/Pivot client application 1.36.2
Published Dec 04, 2025
Tracked Since Feb 18, 2026