PT-2025-38232 · Unknown · Cisa Thorium

Published

2025-08-21

·

Updated

2025-09-18

·

CVE-2025-35433

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CISA Thorium versions prior to 1.1.1
Description CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker possessing a previously used token could potentially log in after a password reset.
Recommendations Update to version 1.1.1 or later.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2026-03193
CVE-2025-35433

Affected Products

Cisa Thorium