← Vulnerability feed

Vulnerability record · CVE-2025-40664 · published 26 May 2025

CVE-2025-40664: Tcman gim missing authentication for critical function vulnerability

Tcman · Gim

Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser and /frmGestionUser.aspx/DeleteUser.

9.3 CVSS 4.0 Critical EPSS 0.55% · top 56.3% CWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser and /frmGestionUser.aspx/DeleteUser.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-40664 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-36276Tcman gim sql injection vulnerabilityTCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerabilit…EPSS 0.77%9.8CVE-2021-40850Tcman gim sql injection vulnerabilityTCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.EPSS 0.94%9.3CVE-2025-40623Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40624Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40625Tcman gim unrestricted file upload vulnerabilityUnrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…EPSS 0.70%9.3CVE-2025-40621Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40622Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40620Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2025-40664), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.