Summary
CVE-2026-12692 is a critical Unverified Password Change vulnerability (CWE-620) in Vimesoft Inc. Enterprise Video Platform, affecting all versions from 3.11.0.0 up to (but not including) 3.25.0. The flaw allows an unauthenticated remote attacker to change any user’s account password without knowledge of the original credentials, resulting in full account takeover. With a CVSS v3.1 base score of 9.8 (Critical), this vulnerability requires no privileges and no user interaction to exploit.
Technical details
- Root cause: The platform’s password change functionality (CWE-620) does not require the requester to authenticate their identity — it fails to verify that the actor initiating a password change is the legitimate account owner or an authorized user. An attacker can supply a target account identifier in the request parameters and set a new password without knowing the original.
- Trigger conditions: The vulnerability is exploitable over the network with no prior authentication, no user interaction, and low attack complexity — meaning any unauthenticated actor with network access to the platform can trigger it.
- Attack vector: Network (HTTP/HTTPS); classified under CAPEC-115 (Authentication Bypass).
- Impact: Successful exploitation grants the attacker full control of the targeted account. This translates to high impact on confidentiality (access to all user data and video content), integrity (ability to modify or delete resources), and availability (ability to lock out legitimate users by changing their passwords).
Affected software
- Vimesoft Inc. Enterprise Video Platform — versions 3.11.0.0 through before 3.25.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to Vimesoft Enterprise Video Platform version 3.25.0 or later, which contains the vendor-issued fix for this vulnerability.
- If immediate patching is not feasible: Restrict network-level access to the Enterprise Video Platform to trusted IP ranges only, and consider placing the platform behind a network access control layer to reduce the unauthenticated attack surface while patching is arranged.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

