Critical severity9.1CISA KEVNVD Advisory· Published Nov 10, 2025· Updated Jun 17, 2026
CVE-2025-12480
CVE-2025-12480
Description
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480nvdExploitThird Party Advisory
- github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.mdnvdThird Party Advisory
- access.triofox.com/releases_history/nvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.triofox.comnvdProduct
News mentions
0No linked articles in our index yet.