Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6
Description
Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Executive Summary:
A critical vulnerability has been identified in multiple Explorance Blue products, assigned CVE-2025-57795 with a CVSS score of 9.9. This flaw allows an authenticated attacker to download arbitrary files from the server, which can be leveraged to gain complete control of the system, leading to remote code execution. Immediate patching is required to prevent potential system compromise and data breaches.
Vulnerability Details
CVE-ID: CVE-2025-57795
Affected Software: Explorance Blue
Affected Versions: Versions prior to 8.14.13. See vendor advisory for a specific list of affected products.
Vulnerability: The vulnerability is an authenticated remote file download flaw within a web service component of the Explorance Blue application. An attacker with valid credentials can exploit this vulnerability by sending a specially crafted request to the web service to download files from the underlying server's file system. In default configurations, this can be escalated to Remote Code Execution (RCE) by downloading sensitive configuration files containing credentials, application source code to identify further weaknesses, or other critical system files.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.9, indicating a high potential for significant business impact. Successful exploitation could lead to a complete compromise of the affected server, allowing an attacker to steal sensitive data, disrupt services, or use the compromised system as a pivot point to attack other internal network resources. The risks include theft of proprietary information or personally identifiable information (PII), reputational damage, financial loss, and potential regulatory penalties.
Remediation Plan
Immediate Action:
Proactive Monitoring:
../,..\\) or requests for sensitive system files (e.g.,web.config,/etc/shadow, credentials files).Compensating Controls:
Exploitation Status
Public Exploit Available: false
Analyst Notes:
As of the publication date of January 28, 2026, there are no known public exploits for this vulnerability. However, due to the critical CVSS score of 9.9 and the direct path to remote code execution, it is highly probable that threat actors will develop and release exploit code in the near future. Organizations should assume this vulnerability will be actively targeted.
Analyst Recommendation
Given the critical severity (CVSS 9.9) and the risk of complete system compromise, this vulnerability poses a severe threat to the organization. The highest priority must be given to applying the vendor-supplied patch across all affected systems immediately. Although this CVE is not currently on the CISA KEV list, its critical nature makes it a prime candidate for future inclusion. We strongly recommend immediate remediation and proactive monitoring for any signs of exploitation.