CVE-2025-5922: Tsplus Remote Access
Medium severity, CVSS 4.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform a brute-force attack using rainbow tables, since the hash is not salted. LTS (Long-Term Support) versions also received patches in v17.2025.6.27 and v16.2025.6.27 releases.
Affected products
- Tsplus Tsplus Remote Access: before v18.40.6.17 (fixed in v18.40.6.17); before v17.2025.6.27 (fixed in v17.2025.6.27); before v16.2025.6.27 (fixed in v16.2025.6.27)
Published 2025-07-29. Last modified 2026-06-17.