High severity8.8NVD Advisory· Published May 20, 2022· Updated Jun 17, 2026
CVE-2022-25227
CVE-2022-25227
Description
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:cybelesoft:thinfinity_vnc:4.0.0.1:*:*:*:*:*:*:*
- Range: =4.0.0.1
Patches
Vulnerability mechanics
References
1- fluidattacks.com/advisories/clapton/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.