PT-2025-49147 · Dctrack · Dctrack

Published

2025-12-04

·

Updated

2025-12-05

·

CVE-2025-66237

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dcTrack (affected versions not specified)
Description dcTrack platforms are susceptible to unauthorized access due to the use of default and hard-coded credentials. An attacker gaining access through these credentials could administer the database, escalate privileges on the platform, and potentially execute system commands on the host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-66237

Affected Products

Dctrack