The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.
Advisories

No advisories yet.

Fixes

Solution

MAXHUB recommends users to upgrade the Pivot client application to v1.36.2 or newer. For more information, see the MAXHUB support page. https://www.maxhub.com/en/support/


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Maxhub
Maxhub pivot
Vendors & Products Maxhub
Maxhub pivot

Thu, 04 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.
Title MAXHUB Pivot Weak Password Recovery Mechanism for Forgotten Password
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-12-04T21:44:06.466Z

Reserved: 2025-07-30T19:03:10.106Z

Link: CVE-2025-53704

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-04T22:15:48.743

Modified: 2025-12-04T22:15:48.743

Link: CVE-2025-53704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-05T10:52:18Z

Weaknesses