---
id: CVE-2025-10539
title: >-
  Due to improper TLS certificate validation in the DeskTime Time Tracking App
  before version 1.3.674, attackers who can position themselves in the network
  path between the client and the DeskTime update servers can return a malicious
  exec…
summary: >-
  Due to improper TLS certificate validation in the DeskTime Time Tracking App
  before version 1.3.674, attackers who can position themselves in the network
  path between the client and the DeskTime update servers can return a malicious
  exec…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-295
  - CWE-296
  - CWE-494
vendor: draugiemgroup
product: desktime_time_tracking
affected:
  - desktime_time_tracking < 1.3.674
patched:
  - desktime_time_tracking 1.3.674
published: '2026-04-28'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10539'
references:
  - url: 'https://desktime.com/download'
    label: 551230f0-3615-47bd-b7cc-93e92e730bbf
  - url: 'https://r.sec-consult.com/desktime'
    label: 551230f0-3615-47bd-b7cc-93e92e730bbf
  - url: 'http://seclists.org/fulldisclosure/2026/Apr/20'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2026/Apr/21'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://sec-consult.com/vulnerability-lab/advisory/missing-tls-certificate-validation-leading-to-rce-in-desktime-time-tracking-app/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00179
epssPercentile: 0.06756
ingestedAt: '2026-09-30T22:27:27.772Z'
---

## Overview

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.

## Affected

- `desktime_time_tracking < 1.3.674`

## Remediation

Upgrade past the affected range:

- `desktime_time_tracking 1.3.674`
