Description
OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.
Published: 2025-10-16
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Opexustech
Opexustech foiaxpress
CPEs cpe:2.3:a:opexustech:foiaxpress:*:*:*:*:*:*:*:*
Vendors & Products Opexustech
Opexustech foiaxpress

Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Opexus
Opexus foiaxpress
Vendors & Products Opexus
Opexus foiaxpress

Fri, 17 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Oct 2025 17:45:00 +0000

Type Values Removed Values Added
Description OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.
Title OPEXUS FOIAXpress unauthenticated administrator password reset
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Red'}


Subscriptions

Opexus Foiaxpress
Opexustech Foiaxpress
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-02-26T16:57:25.629Z

Reserved: 2025-10-16T16:16:49.618Z

Link: CVE-2025-62586

cve-icon Vulnrichment

Updated: 2025-10-17T15:07:03.652Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-16T18:15:40.637

Modified: 2025-10-29T20:07:15.287

Link: CVE-2025-62586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-20T13:25:03Z

Weaknesses