CVE-2025-53704

7.5

MAXHUB · Pivot client application

The password reset mechanism in the MAXHUB Pivot client application contains a weakness that may allow an unauthenticated attacker to take over a user account.

Executive summary

A critical vulnerability in the MAXHUB Pivot client application password reset mechanism allows unauthenticated attackers to perform account takeover, posing a significant risk to user data and system integrity.

Vulnerability

This vulnerability is classified as CWE-640, indicating a flaw in the password reset process. The weakness allows an unauthenticated attacker to manipulate the reset flow, leading to potential unauthorized account access.

Business impact

The ability for an unauthorized party to reset any account password without authentication presents a severe risk to organizational security. Successful exploitation could lead to full account compromise, unauthorized access to sensitive data, and potential lateral movement within the environment. With a CVSS score of 7.5, this vulnerability is classified as High, reflecting the significant potential for impact despite the absence of reported active exploitation.

Remediation

Immediate Action: Administrators must upgrade the Pivot client application to version 1.36.2 or newer immediately to apply the vendor-provided fix.

Proactive Monitoring: Security teams should monitor authentication logs for unusual patterns of password reset requests or unexpected account modifications.

Compensating Controls: If immediate patching is not feasible, restrict access to the Pivot client network segments and enforce additional multi-factor authentication where supported by the underlying infrastructure.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the severity of an account takeover vulnerability, organizations using the MAXHUB Pivot client application should prioritize this update. Applying the patch to version 1.36.2 is the only definitive method to remediate this flaw and prevent potential unauthorized access to your systems.

Sources

Originally found and disclosed by Malik MAKKES of Abicom Groupe OCI reported this vulnerability to MAXHUB., per the CVE Program record.