CVE-2025-54459: Vertikalsystems Hospital Manager Backend Services

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

Affected products

  • Vertikalsystems Hospital Manager Backend Services: up to and including 2025-09-19

Published 2025-10-29. Last modified 2026-10-08.