External risk intelligence

WorkExaminer Console Administrative Access Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-10640

The vulnerability involves a management console listening on a specific TCP port (12306). While this service is intended for administrative use and likely restricted to internal networks in many deployments, it is network-reachable and could be exposed to the internet if misconfigured or if specific administrative access requirements necessitate such exposure.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated attacker can exploit a flaw in the WorkExaminer Professional console to bypass login and gain administrative control. This vulnerability affects the server used for administrative access, potentially exposing sensitive monitoring data, including user screenshots and keystrokes.

  • Attackers bypass console login for admin control.
  • Exposes sensitive user monitoring data to unauthorized access.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach the WorkExaminer server on TCP port 12306, bypassing the login prompt by exploiting missing server-side authentication checks. This allows them to gain administrative access, leading to the exposure of sensitive monitoring data, including screenshots and keystrokes.

  • Attacker needs network access to the port.
  • Bypasses login via missing server checks.
  • Gains admin access, exposing sensitive data.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could gain administrative access to the WorkExaminer server by bypassing login prompts when the server is accessible via TCP port 12306. This could expose sensitive monitoring data, including screenshots and keystrokes of all users.

  • Sensitive monitoring data at risk.
  • Bypass login via network access.
  • Unauthorized access to user data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WorkExaminer Professional console, used for server administration, is vulnerable due to missing server-side authentication checks. This allows unauthenticated attackers on TCP port 12306 to bypass login, gain administrative access, and access sensitive monitoring data, including screenshots and keystrokes. Infrastructure or platform teams responsible for the WorkExaminer server should prioritize identifying all instances, assessing their network reachability and business criticality, and confirming the accountable owner before planning remediation.

  • Infrastructure and platform teams own the issue.
  • Verify server reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WorkExaminer Professional?

WorkExaminer Professional is a software platform designed for employee activity monitoring. It collects detailed sensitive data from client machines, including saved screenshots and recorded keystrokes, and manages this information through a centralized server console used by administrators.

How does CVE-2025-10640 allow login bypass?

This vulnerability is a client-side enforcement weakness, categorized as CWE-602. The WorkExaminer server fails to verify authentication results, trusting the client application to confirm identity. An attacker can manipulate this interaction to skip the password prompt entirely and assume administrative privileges.

Do I need to be authenticated to trigger this bug?

No. The vulnerability exists because the server does not enforce authentication checks on TCP port 12306. Any attacker with network connectivity to this specific port can trigger the flaw; local user access or prior credentials are not required for exploitation.

Why should I care if my WorkExaminer server is external?

According to Halo Surface Signal, this management port is often meant for internal use. If your server is reachable from the internet, the barrier for an attacker is significantly lower, as they can attempt to reach port 12306 remotely without needing access to your internal corporate network.

What is the first step to address this CVE?

Start by identifying all WorkExaminer server instances in your environment. Confirm their current network reachability, specifically checking if TCP port 12306 is exposed to untrusted networks. Once identified, coordinate with the server owners to restrict access to the administration port.

References