CVE-2025-2562: Devolutions Remote Desktop Manager
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.
Affected products
- Devolutions Remote Desktop Manager: before 2024.3.31.0 (fixed in 2024.3.31.0); from 2025.1.24.0, before 2025.1.26.0 (fixed in 2025.1.26.0)
Published 2025-03-26. Last modified 2026-06-17.