๐Ÿ” CVE Alert

CVE-2025-5309

UNKNOWN 0.0

Remote Support & Privileged Remote Access server side template injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

CWE CWE-94
Vendor beyondtrust
Product remote support & privileged remote access
Published Jun 16, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for beyondtrust remote support & privileged remote access

Be the first to know when new unknown vulnerabilities affecting beyondtrust remote support & privileged remote access are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

BeyondTrust / Remote support & Privileged Remote Access
24.2.2 โ‰ค 24.2.4 24.3.1 โ‰ค 24.3.3 25.1.1
BeyondTrust / Remote Support(RS) & Privileged Remote Access(PRA)
24.2.2 โ‰ค 24.2.4 24.3.1 โ‰ค 24.3.4 25.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
beyondtrust.com: https://www.beyondtrust.com/trust-center/security-advisories/bt25-04

Credits

Jorren Geurts of Resillion