CVE-2025-10539 Details
Description
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.
A remote code execution vulnerability has been identified in the DeskTime Time Tracking App, affecting versions prior to 1.3.674. The issue arises from improper validation of TLS certificates, allowing attackers to intercept update requests and deliver malicious executables. This exploitation results in user-level remote code execution on the affected client.
Users can update to DeskTime version 1.3.674, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec-consult.com/vulnerability-lab/advisory/missing-tls-certificate-validation-leading-to-rce-in-desktime-time-tracking-app/ | CISA-ADP | Third Party Advisory |
| https://desktime.com/download | SEC Consult Vulnerability Lab | Product |
| https://r.sec-consult.com/desktime | SEC Consult Vulnerability Lab | Third Party Advisory |
| http://seclists.org/fulldisclosure/2026/Apr/20 | CVE | ExploitMailing ListThird Party Advisory |
| http://seclists.org/fulldisclosure/2026/Apr/21 | CVE | ExploitMailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | SEC Consult Vulnerability Lab |
| CWE-296 | Improper Following of a Certificate's Chain of Trust | SEC Consult Vulnerability Lab |
| CWE-494 | Download of Code Without Integrity Check | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| draugiemgroup desktime time tracking | < 1.3.674 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | CVE Modified | CVE |
| Apr 28, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | New CVE Received | SEC Consult Vulnerability Lab |