CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-50433

Critical · CVSS 9.8

imonnit.com (Monnit IoT Monitoring Platform) — Account Takeover via Weak/Improper Password Reset (CWE-640)

CVSS
9.8
nvd
EPSS
0.42%
34th pct
KEV
No
Class
other
CWE-640

Description

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

Search profile — drives PoC discovery

Symbols password_resetreset_tokenaccount_takeoverprivilege_escalationcrafted_password_resetarbitrary_user_accountimonnit
Keywords CVE-2025-50433imonnitimonnit.comaccount takeoverpassword resetprivilege escalationCWE-6400xMandorimonnit-ato-advisoryMonnitATO advisory
Versions: Affected as of 2025-04-24

Ranked PoCs (3) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z