CVE-2025-10639
8.8EfficientLab · WorkExaminer Professional
EfficientLab WorkExaminer Professional uses hardcoded credentials in its FTP server, allowing authenticated attackers to gain SYSTEM-level remote code execution.
Executive summary
A critical vulnerability in the WorkExaminer Professional FTP server allows authenticated attackers to gain full administrative control over the host system.
Vulnerability
The application utilizes hardcoded credentials for its FTP service on port 12304, which allows an authenticated user to perform unauthorized file operations and achieve remote code execution as NT AUTHORITY\SYSTEM by replacing service binaries.
Business impact
Successful exploitation grants an attacker full SYSTEM-level access to the server, resulting in total compromise of confidentiality, integrity, and availability. With a CVSS score of 8.8, this vulnerability poses a severe risk to organizational infrastructure, as it enables lateral movement and persistent control over sensitive monitoring data.
Remediation
Immediate Action: As no official patch is currently available, immediately restrict network access to TCP port 12304 to trusted internal segments only and consider disabling the vulnerable FTP service entirely if it is not business-critical.
Proactive Monitoring: Monitor network traffic directed to port 12304 for unusual login patterns and inspect the WorkExaminer installation directory for unexpected modifications to service binaries or executable files.
Compensating Controls: Implement strict network segmentation or place the server behind a firewall that denies all unauthorized access to the affected FTP port, effectively isolating the service from potential attackers.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical write-up provided by SEC Consult.
Analyst recommendation
Given the vendor's failure to provide a security update and the potential for full system compromise, this product should be considered unmaintained and highly insecure. Organizations using WorkExaminer Professional must isolate the affected server from the network immediately and evaluate migrating to a supported, secure alternative to eliminate this critical exposure.
Sources
Originally found and disclosed by Tobias Niemann, SEC Consult Vulnerability Lab, Daniel Hirschberger, SEC Consult Vulnerability Lab, Thorger Jansen, SEC Consult Vulnerability Lab, Marius Renner, SEC Consult Vulnerability Lab, per the CVE Program record.