logo

A Vulnerability in Trimble Cityworks Could Allow for Remote Code Execution

ID: 04257317-b39b-5d46-8a8b-9cd52d422452

STIX ID: report--04257317-b39b-5d46-8a8b-9cd52d422452

Feed Name: CISecurity.org Advisories

Threat Score
65/100

Date Published: 2025-02-06

Date Updated: 2026-04-27

...
...

A deserialization vulnerability (CVE-2025-0994) in Trimble Cityworks and Cityworks with Office Companion could allow an authenticated user to perform remote code execution against Microsoft IIS hosting the product, potentially enabling installation of programs and modification or deletion of data depending on account privileges; the report notes the impact but does not provide evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.