Tsplus develops remote-access and remote-work solutions that enable secure connectivity and session management for distributed workforces, with its vulnerability profile centered on the recurring products Tsplus Remote Work and Tsplus Remote Access. The durable signal across observed disclosures centers on credential and permission handling, with recurrent weaknesses in default permissions configuration, cleartext storage of sensitive information, and insufficiently protected credential storage that reflect the authentication and access-control demands of remote-connectivity platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tsplus over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31069CRITICAL An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. | Sep 11, 2023 | 9.8 | 38 | NO | YES |
CVE-2023-31068CRITICAL An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\ | Sep 11, 2023 | 9.8 | 38 | NO | YES |
CVE-2023-31067CRITICAL An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www. | Sep 11, 2023 | 9.8 | 38 | NO | YES |
CVE-2023-27133CRITICAL TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escala | Oct 17, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-27132CRITICAL TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about | Oct 17, 2023 | 9.8 | 24 | NO | NO |
CVE-2025-5922MEDIUM Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's | Jul 29, 2025 | 4.8 | 19 | NO | NO |
CVE-2025-26318MEDIUM hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application. | Mar 4, 2025 | 5.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tsplus.
Media articles that mention a CVE ID that affects a product developed by Tsplus — matched by CVE ID, not by vendor name.