Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
CVE-2025-10641: WorkExaminer Professional sends sensitive data unencrypted over the network
CVE-2025-10641 · published 10 months ago
Summary
WorkExaminer Professional transmits sensitive data in plain text, allowing unauthorized network access to intercept and modify it. This could lead to data theft or tampering. To protect sensitive data, consider using encryption or a secure alternative to FTP.
Original advisory text
All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the transmitted sensitiv...
All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the transmitted sensitive data. An attacker can also freely modify the data on the wire. The monitoring clients transmit their data to the server using the unencrypted FTP. Clients connect to the FTP server on port 12304 and transmit the data unencrypted. In addition, all traffic between the console client and the server at port 12306 is unencrypted.
Severity
7.1
High
CVSS 3.1: 7.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-319Cleartext Transmission of Sensitive Information
Timeline
Published21 Oct 2025
Updated15 Aug 2026
First seen7 Mar 2026
Sources
CVE-2025-10641 · NVD
Monitor software like this
Free during beta