CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-63747

Critical · CVSS 9.8

QaTraq — Default Credentials / Weak Password Policy (CWE-521)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-521

Description

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access.

Search profile — drives PoC discovery

Symbols login pageadministrative accountdefault credentialsadmin loginweb application login
Keywords CVE-2025-63747QaTraqQaTraq 6.9.2default credentialsdefault passwordadmin credentialsweak password policyCWE-521QaTraq RCEQaTraq file uploadQaTraq authentication bypassbitsbyamg QaTraq
Versions: 6.9.2

Ranked PoCs (23) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z