PT-2025-39391 · Unknown · Imonitor Eam

Published

2025-09-25

·

Updated

2025-09-25

·

CVE-2025-10542

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iMonitor EAM version 9.6394
Description The software ships with default administrative credentials that are displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This allows reading sensitive telemetry, including keylogger output, and issuing arbitrary actions to all connected clients.
Recommendations Change the default administrative credentials.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-10542

Affected Products

Imonitor Eam