Vulnerability Description
The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT Authority\SYSTEM on the server by exchanging accessible service binaries in the WorkExaminer installation directory (e.g. "C:\Program File (x86)\Work Examiner Professional Server").
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-10639?
CVE-2025-10639 is a vulnerability with a CVSS score of 8.8 (HIGH). The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcode...
How severe is CVE-2025-10639?
CVE-2025-10639 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10639?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.