Vulnerability Description
Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tonec | Internet Download Manager | <= 6.42.41.1 |
Related Weaknesses (CWE)
References
- http://tonec.comProduct
- https://www.notion.so/CVE-2025-56231-2a04e9f2a40d80b184f4d02be58d3600ExploitThird Party Advisory
FAQ
What is CVE-2025-56231?
CVE-2025-56231 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.
How severe is CVE-2025-56231?
CVE-2025-56231 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-56231?
Check the references section above for vendor advisories and patch information. Affected products include: Tonec Internet Download Manager.