PT-2026-4740 · Unknown · Exos 9300 Server

Published

2026-01-26

·

Updated

2026-01-27

·

CVE-2025-59090

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions exos 9300 server (affected versions not specified)
Description A SOAP API is reachable on port 8002 on the exos 9300 server without requiring authentication. Network access to the server allows for actions such as creating arbitrary access log events and querying two-factor authentication (2FA) PINs associated with enrolled chip cards. The API endpoint is ''/'' on port 8002.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-59090

Affected Products

Exos 9300 Server