CVE-2022-25226 is a critical authentication bypass vulnerability affecting ThinVNC version 1.0b1, allowing unauthenticated attackers to obtain a valid session ID. This flaw, rated 10.0 CVSS (CRITICAL), enables remote code execution on the server with low attack complexity via network access. The vulnerability has a high EPSS score (0.81886) and a FAUCET Risk Score of 89.0, indicating a very high probability of exploitation. Publicly available exploit code exists via Nuclei templates and GitHub, and it has garnered significant community discussion, underscoring its immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:cybelsoft:thinvnc:1.0:b1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.