An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

Published: 2025-05-13

CVSS: 7.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Download CVE-2025-4427 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

https://connollyfinan.ie/poc-259-cve-2024-12356/

https://connollyfinan.ie/poc-282-cve-2016-0800/

https://connollyfinan.ie/poc-654-cve-2024-3660/

https://connollyfinan.ie/poc-348-cve-2014-0114/