CVE-2025-58385: Doxense Watchdoc

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded and predictable data).

Affected products

  • Doxense Watchdoc: before 6.1.1 (fixed in 6.1.1)

Published 2025-09-26. Last modified 2026-06-17.