PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-69133 GoodLayers CVE debrief

A CVE record for a Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions was published on 2026-07-02T12:16:53.300Z and last modified on 2026-10-06T22:10:00.247Z. The NVD entry is currently Deferred.

Vendor
GoodLayers
Product
Tourmaster
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-02
Original CVE updated
2026-10-06
Advisory published
2026-07-02
Advisory updated
2026-10-06

Who should care

Defenders responsible for Tourmaster installations, particularly those using versions 5.4.5 and earlier, should assess exposure and prioritize verification and potential mitigations.

Why it matters

CVE-2025-69133 describes a Subscriber Local File Inclusion vulnerability in Tourmaster versions 5.4.5 and earlier. Defenders responsible for Tourmaster installations should assess exposure, verify versions, and prioritize updates or mitigations to prevent potential exploitation.

  • Verification of Tourmaster version and exposure is necessary to determine potential vulnerability.
  • Potential Local File Inclusion could lead to unauthorized access or data breaches if exploited.
  • Defenders should prioritize updates or mitigations to prevent potential exploitation.

Technical summary

The CVE record describes a Subscriber Local File Inclusion vulnerability in Tourmaster versions 5.4.5 and earlier. The CVSS score is 7.5 with a High severity. The vulnerability has been assigned CWE-98.

Defensive priority

Defenders should prioritize verifying exposure of Tourmaster versions 5.4.5 and earlier, and assess the need for updates or mitigations.

Recommended defensive actions

  • Verify Tourmaster version and assess exposure
  • Review and apply updates or mitigations as necessary
  • Monitor for potential exploitation attempts

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, with the primary source being Patchstack. Further verification of affected versions and potential impacts is required.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-69133 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-69133

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-69133 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-69133

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.