TSplus Remote Access Insecure Permissions Information Disclosure Vulnerability

Vulnerability

A vulnerability in TSplus Remote Access versions prior to 17.30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application. This information disclosure flaw can be exploited through an unauthenticated HTTP request to the hb.exe endpoint.

Impact

Exploitation of this vulnerability allows for the retrieval of connected domain accounts, which can be used for targeted phishing or vishing attacks, and could facilitate further intrusions.

Reproduction

The vulnerability can be reproduced by sending an unauthenticated HTTP request to the /cgi-bin/hb.exe endpoint. This request will trigger the endpoint to respond with a list of all domain accounts currently connected to the TSplus application.

Remediation

TSplus has released a patch for this vulnerability in the beta version of Remote Access. The patch removes the user listing from the /cgi-bin/hb.exe endpoint and introduces a new endpoint, /api/loadbalancing/load, on port 19955, which requires signed messages with a timestamp for authentication.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
9.7
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.