CVE-2025-10227: Axxonsoft Axxon One

Medium severity, CVSS 4.6. EPSS: 0.1% chance of exploitation in the next 30 days.

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.

Affected products

  • Axxonsoft Axxon One: before 2.0.8 (fixed in 2.0.8)

Published 2025-09-10. Last modified 2026-09-26.