EfficientLab WorkExaminer Professional FTP Server Vulnerability Allowing Unauthorized Access and Remote Code Execution

Vulnerability

A vulnerability exists in EfficientLab WorkExaminer Professional server installations through version 4.0.0.52001. The FTP server, active on TCP port 12304, can be accessed by an attacker with network reach to that port using weak hardcoded credentials. This access allows the attacker to read or modify data and log files. Furthermore, it enables remote code execution on the server as NT Authority\SYSTEM by replacing service binaries in the WorkExaminer installation directory.

Impact

Exploitation of this vulnerability leads to unauthorized access to the FTP server, allowing for data manipulation and log file access. More critically, it facilitates remote code execution on the server with SYSTEM privileges.

Reproduction

To reproduce this vulnerability, an attacker must have network access to the WorkExaminer server's FTP port (12304). Using the hardcoded FTP credentials, the attacker can log into the FTP server, access sensitive data, and overwrite WorkExaminer service binaries to execute arbitrary code on the server as NT Authority\SYSTEM.

Added: Oct 21, 2025, 12:18 PM
Updated: Oct 21, 2025, 8:08 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.7
remediation
0.0
relevance
0.8
threat
1.6
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.