{"id":"CVE-2025-12480","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-12480","summary":"Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.","details":"Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.","published":"2025-11-10T14:20:40.677Z","modified":"2026-02-26T17:47:04.149Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.90532,"percentile":0.99793,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2025-11-12","dueDate":"2025-12-03","knownRansomwareCampaignUse":false},"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md"},{"type":"WEB","url":"https://www.triofox.com/"},{"type":"WEB","url":"https://access.triofox.com/releases_history/"},{"type":"ADVISORY","url":"https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-02-26T17:47:04.149Z"}}