CVE-2025-40669: Tcman Gim
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.
Affected products
- Tcman Gim: version 11.0 only
Published 2025-06-09. Last modified 2026-06-17.