CVE-2025-63747

Q

aTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access.

Configurations

Configuration 1 (hide)

cpe:2.3:a:testmanagement:qatraq:6.9.2:*:*:*:*:*:*:*

History

26 Nov 2025, 15:50

Type Values Removed Values Added
CPE cpe:2.3:a:testmanagement:qatraq:6.9.2:*:*:*:*:*:*:*
References () http://qatraq.com - () http://qatraq.com - Broken Link
References () https://bitsbyamg.com/blog/post/2025/10/19/qatraq-692-default-creds-and-file-upload-rce - () https://bitsbyamg.com/blog/post/2025/10/19/qatraq-692-default-creds-and-file-upload-rce - Exploit, Third Party Advisory
First Time Testmanagement
Testmanagement qatraq

17 Nov 2025, 20:15

Type Values Removed Values Added
CWE CWE-521
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

17 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-17 16:15

Updated : 2025-11-26 15:50


NVD link : CVE-2025-63747

Mitre link : CVE-2025-63747

CVE.ORG link : CVE-2025-63747


JSON object : View

Products Affected
CWE
CWE-521

Weak Password Requirements