CVE-2025-54834: Opexustech Foiaxpress Public Access Link

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.

Affected products

  • Opexustech Foiaxpress Public Access Link: from 11.1.0, before 11.12.3.0 (fixed in 11.12.3.0)

Published 2025-07-31. Last modified 2026-06-17.