CVE-2025-2562: Devolutions Remote Desktop Manager

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.

Affected products

  • Devolutions Remote Desktop Manager: before 2024.3.31.0 (fixed in 2024.3.31.0); from 2025.1.24.0, before 2025.1.26.0 (fixed in 2025.1.26.0)

Published 2025-03-26. Last modified 2026-06-17.