Insufficient Session Expiration in AxxonOne Web Admin Panel
CVE-2025-10223
What is CVE-2025-10223?
The AxxonSoft Axxon One Web Admin Panel has a vulnerability that stems from insufficient session expiration mechanisms. This issue permits both local and remote authenticated attackers to maintain access privileges even after they should have been revoked. The vulnerability arises when an attacker continues to use an unexpired session token, thereby bypassing the intended security controls. The persistent session allows attackers to exploit previously authorized access until the session naturally expires, which does not occur in a timely manner. Organizations using Axxon One should prioritize upgrading to version 2.0.3 or newer to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AxxonOne C-Werk Windows 0 <= 2.0.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
