PT-2025-39391 · Unknown · Imonitor Eam
Published
2025-09-25
·
Updated
2025-09-25
·
CVE-2025-10542
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iMonitor EAM version 9.6394
Description
The software ships with default administrative credentials that are displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This allows reading sensitive telemetry, including keylogger output, and issuing arbitrary actions to all connected clients.
Recommendations
Change the default administrative credentials.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imonitor Eam