peter bassill · operator
$ cve CVE-2022-25226 JSON

CVE-2022-25226

10.0
CRITICAL · CVSS 3.1 · EPSS 11% (pctl 96)

Patch early

EPSS 11% — above the 10% action threshold.

Description

ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS10.99% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploitnone known
Published2022-04-18
Last modified2026-06-17

Affected (1)

VendorProduct
cybelsoftthinvnc

References

→ the Explorer  ·  watch your stack  ·  NVD