CVE Database
/

CVE-2025-5922

Back to search

CVE-2025-5922

Published: Jul 29, 2025

Modified: Jul 29, 2025

PUBLISHED

Description

Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform a brute-force attack using rainbow tables, since the hash is not salted. LTS (Long-Term Support) versions also received patches in v17.2025.6.27 and v16.2025.6.27 releases.

VendorProductVersions

TSplus

TSplus Remote Access

affected
0 - < v18.40.6.17
affected
0 - < v17.2025.6.27
affected
0 - < v16.2025.6.27

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now