CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-56231

Critical · CVSS 9.1

Tonec Internet Download Manager (IDM) — Missing SSL Certificate Validation (CWE-295)

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-295

Description

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

Search profile — drives PoC discovery

Symbols SSL certificate validationupdate checkHTTPS verificationcertificate pinningupdate protection bypass
Keywords CVE-2025-56231Internet Download ManagerIDMSSL certificate validationmissing certificate validationupdate bypassTonecIDM 6.42MitM updateCWE-295
Versions: <= 6.42.41.1

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z