CVE-2025-10539
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.
| CWE | CWE-295 CWE-296 CWE-494 |
| Vendor | desktime |
| Product | desktime time tracking app |
| Published | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for desktime desktime time tracking app
Be the first to know when new unknown vulnerabilities affecting desktime desktime time tracking app are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
DeskTime / DeskTime Time Tracking App
0 < 1.3.674
References
Credits
Daniel Hirschberger, SEC Consult Vulnerability Lab Thorger Jansen, SEC Consult Vulnerability Lab Tobias Niemann, SEC Consult Vulnerability Lab Marius Renner, SEC Consult Vulnerability Lab