Record summary

CVE-2025-57789 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 21, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List11.32.0 to ≤ 11.32.101affected
11.36.0 to ≤ 11.36.59affected

Nuclei templates

1
ProjectDiscoveryMEDIUMCommvault Initial Administrator Login Process Vulnerability

An issue was discovered in Commvault before 11.36.60.During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

Impact

Attackers can exploit default credentials during the brief setup window between installation and first administrator login to gain admin control of the Commvault instance.

Remediation

Complete the initial administrator setup immediately after installation and change all default credentials.

AuthorsDhiyaneshDK, watchtowr
Template tagscvecve2025commandcentercommvaultunauthvuln
Shodan: http.favicon.hash:-542502280

Source: ProjectDiscovery

References

2