CVE-2025-13683

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
28/11/2025
Last modified:
18/12/2025

Description

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* 2025.3.10.0 (excluding)
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:windows:*:* 2025.3.25.0 (excluding)


References to Advisories, Solutions, and Tools