VYPR

Triofox

by Triofox

CVEs (2)

  • CVE-2025-12480CriKEVNov 10, 2025
    risk 0.78cvss 9.1epss 0.91

    Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

  • CVE-2026-8360HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not…