CVE-2025-10641

7.1

EfficientLab · WorkExaminer Professional

WorkExaminer Professional transmits all traffic between clients, consoles, and servers in cleartext over FTP and custom ports, allowing for data interception and modification.

Executive summary

EfficientLab WorkExaminer Professional suffers from cleartext communication vulnerabilities that allow unauthorized attackers to intercept or modify sensitive monitoring data.

Vulnerability

This is a cleartext transmission of sensitive information (CWE-319) occurring over FTP (port 12304) and custom traffic channels (port 12306), requiring low privileges to exploit.

Business impact

The lack of encryption allows attackers with network access to perform man-in-the-middle attacks, leading to the exposure of sensitive monitoring data and the potential for unauthorized data manipulation. With a CVSS score of 7.1, this high-severity vulnerability poses a significant risk to organizational confidentiality and integrity, as the monitoring software effectively transmits credentials and private employee activity data in the clear.

Remediation

Immediate Action: Since the vendor has not provided a patch and the product may be unmaintained, users should immediately restrict network access to the affected ports (12304 and 12306) to trusted segments only.

Proactive Monitoring: Monitor network traffic for unauthorized connections to these ports and inspect logs for anomalous activity from internal hosts that could indicate an intercept attempt.

Compensating Controls: Deploy the application within an isolated VLAN or wrap the communication in a secure VPN or TLS-terminating tunnel to force encryption of the cleartext traffic.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given that the vendor has not committed to a fix, this software should be considered high-risk for any environment requiring data security. Organizations currently utilizing WorkExaminer Professional should prioritize migrating to a more secure, actively maintained alternative to eliminate the risk of cleartext traffic interception.

Sources

Originally found and disclosed by Tobias Niemann, SEC Consult Vulnerability Lab, Daniel Hirschberger, SEC Consult Vulnerability Lab, Thorger Jansen, SEC Consult Vulnerability Lab, Marius Renner, SEC Consult Vulnerability Lab, per the CVE Program record.