CVE 9.8 CRITICAL

CVE-2025-54303_CVE-2025-54303

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a password change policy for default administrative accounts is not enforced. Many deployments may retain default credentials, in which case an attacker is likely to be able to successfully authenticate with administrative privileges.

AI Analysis

Weak default credentials in Thermo Fisher Torrent Suite Django application

Basic Information

ID CVE-2025-54303
Source mitre
Published Dec 4, 2025 at 00:00
Modified Dec 5, 2025 at 20:05

Affected Product

Vendor Thermo Fisher
Product Torrent Suite
Version 5.18.1
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Thermo Fisher
Product Torrent Suite
Version 5.18.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.