Insecure Default Admin Credentials Enable Full Administrative Access in iMonitor EAM
Vulnerability Description
iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This enables reading highly sensitive telemetry (including keylogger output) and issuing arbitrary actions to all connected clients.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10542
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Marius Renner, SEC Consult Vulnerability Lab
- Daniel Hirschberger, SEC Consult Vulnerability Lab
- Tobias Niemann, SEC Consult Vulnerability Lab
- Thorger Jansen, SEC Consult Vulnerability Lab
References
Affected Vendor
iMonitor Software Inc.
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.