A critical vulnerability has been identified in the password recovery mechanism of the MAXHUB Pivot client application, tracked as CVE-2025-53704. The flaw allows remote attackers to exploit the weak password reset process, potentially enabling unauthorized account takeover. The vulnerability affects all versions of the Pivot client application prior to v1.36.2, and has been assigned a CVSS v4 base score of 8.7, indicating high severity and low attack complexity.
MAXHUB has released an update to address the issue, recommending users upgrade to version 1.36.2 or newer to mitigate the risk. CISA has also advised organizations to minimize network exposure of control system devices, place them behind firewalls, and isolate them from business networks to reduce the likelihood of exploitation. The vulnerability was reported by Malik MAKKES of Abicom Groupe OCI, and impacts organizations worldwide, particularly those in the information technology sector.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The MAXHUB Pivot weak password recovery vulnerability was publicly listed as CVE-2025-53704 in vulnerability databases and feeds. Public references linked the issue to CISA's advisory and MAXHUB remediation guidance.
CISA issued ICS advisory ICSA-25-338-02 describing CVE-2025-53704, a high-severity account takeover vulnerability in MAXHUB Pivot with CVSS v4 8.7 and CVSS v3.1 7.5. CISA said the product is deployed worldwide in the IT sector and noted there was no known public exploitation at the time of publication.
MAXHUB recommended upgrading to Pivot client version 1.36.2 or newer to fix CVE-2025-53704, a weak password recovery issue affecting all prior versions. The vulnerability is tracked as CWE-640 and is remotely exploitable.
Malik MAKKES of Abicom Groupe OCI reported a weak password recovery vulnerability in the MAXHUB Pivot client application to MAXHUB. The flaw could allow a remote attacker to reset passwords and take over accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.