CVE-2025-5922 describes an information disclosure vulnerability in TSplus Remote Access versions below v18.40.6.17 (and specific LTS versions). The PIN hash for the Admin Tool, which is typically restricted to administrators, is stored unsalted in a system registry accessible to regular users. This allows for offline brute-force attacks using rainbow tables to discover the PIN. Rated with a CVSS score of 4.8 (Medium), the vulnerability has a local attack vector and low attack complexity, but its impact is limited to confidentiality. Successful exploitation could grant unauthorized administrative access to the Remote Access Admin Tool. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage has been observed for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < v16.2025.6.27CPE match | cpe:2.3:a:tsplus:tsplus_remote_access:*:*:*:*:*:*:*:* | ||
>= 0, < v17.2025.6.27CPE match | cpe:2.3:a:tsplus:tsplus_remote_access:*:*:*:*:*:*:*:* | ||
>= 0, < v18.40.6.17CPE match | cpe:2.3:a:tsplus:tsplus_remote_access:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.