High severity7.5NVD Advisory· Published Oct 29, 2025· Updated Jun 17, 2026
CVE-2025-54459
CVE-2025-54459
Description
Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:vertikalsystems:hospital_manager_backend_services:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vertikalsystems:hospital_manager_backend_services:*:*:*:*:*:*:*:*range: <=2025-09-19
- (no CPE)range: 0
- Range: <2025-09-19
Patches
Vulnerability mechanics
References
1- www.cisa.gov/news-events/ics-medical-advisories/icsma-25-301-01nvdMitigationThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.