CVE-2025-6523
HIGHDevolutions Server <2025.2.3.0 - Auth Bypass
Title source: llmDescription
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier
Scores
CVSS v3
7.7
EPSS
0.0011
EPSS Percentile
30.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Classification
CWE
CWE-1391
Status
published
Affected Products (1)
devolutions/devolutions_server
< 2025.1.11.0
Timeline
Published
Jul 22, 2025
Tracked Since
Feb 18, 2026