CVE-2025-35433: CISA Thorium does not properly invalidate previously used tokens
Published Sep 17, 2025
·Updated
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.
Affected Software
2 affected components
CISA Thorium<1.1.1
CISA Thorium=1.1.0
Remediation
Event History
Sep 17, 2025
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-35433?
CVE-2025-35433 has a high severity due to the potential for unauthorized access after password resets.
2
How do I fix CVE-2025-35433?
To fix CVE-2025-35433, update CISA Thorium to version 1.1.1 or later.
3
What impact does CVE-2025-35433 have on my system?
CVE-2025-35433 allows an attacker to reuse previously valid tokens to gain unauthorized access even after a password reset.
4
Is CVE-2025-35433 an exploit that is being widely targeted?
While there is no specific data indicating widespread targeting of CVE-2025-35433, its high severity makes it a significant risk.
5
What systems are affected by CVE-2025-35433?
CVE-2025-35433 affects CISA Thorium versions prior to 1.1.1.