CVE-2025-54833 Details
Description
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.
A vulnerability in OPEXUS FOIAXpress Public Access Link (PAL) version 11.1.0 allows unauthenticated remote attackers to bypass account-lockout and CAPTCHA protections. This vulnerability makes it easier to brute force passwords. The issue has been addressed in version 11.12.3.0.
Users are advised to upgrade to OPEXUS FOIAXpress PAL version 11.12.3.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 7, 2025CISA-ADP
Assessed Aug 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.opexustech.com/docs/foiaxpress/11.12.0/FOIAXpress_Release_notes_11.12.3.0.pdf | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Release Notes |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-174-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Product |
| https://www.cve.org/CVERecord?id=CVE-2025-54833 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-602 | Client-Side Enforcement of Server-Side Security | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| opexustech foiaxpress public access link | >= 11.1.0, < 11.12.3.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Modified Analysis | [email protected] |
| Sep 12, 2025 | Initial Analysis | [email protected] |
| Jul 31, 2025 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |