CVE-2025-10225: Axxonsoft Axxon One

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.

Affected products

  • Axxonsoft Axxon One: up to and including 2.0.6

Published 2025-09-10. Last modified 2026-09-26.