CVE-2025-40669 HIGH

CVE-2025-40669: Incorrect Authorization vulnerability in TCMAN GIM

Vendor Tcman
Product GIM
Weakness CWE-863 · Incorrect authorization
Published June 9, 2025
Last update June 9, 2025

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.

Key dates

02Disclosure timeline

June 9, 2025 CVE published
June 9, 2025 Record updated