PatchSiren cyber security CVE debrief
CVE-2025-69133 GoodLayers CVE debrief
A CVE record for a Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions was published on 2026-07-02T12:16:53.300Z and last modified on 2026-10-06T22:10:00.247Z. The NVD entry is currently Deferred.
- Vendor
- GoodLayers
- Product
- Tourmaster
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-02
- Original CVE updated
- 2026-10-06
- Advisory published
- 2026-07-02
- Advisory updated
- 2026-10-06
Who should care
Defenders responsible for Tourmaster installations, particularly those using versions 5.4.5 and earlier, should assess exposure and prioritize verification and potential mitigations.
Why it matters
CVE-2025-69133 describes a Subscriber Local File Inclusion vulnerability in Tourmaster versions 5.4.5 and earlier. Defenders responsible for Tourmaster installations should assess exposure, verify versions, and prioritize updates or mitigations to prevent potential exploitation.
- Verification of Tourmaster version and exposure is necessary to determine potential vulnerability.
- Potential Local File Inclusion could lead to unauthorized access or data breaches if exploited.
- Defenders should prioritize updates or mitigations to prevent potential exploitation.
Technical summary
The CVE record describes a Subscriber Local File Inclusion vulnerability in Tourmaster versions 5.4.5 and earlier. The CVSS score is 7.5 with a High severity. The vulnerability has been assigned CWE-98.
Defensive priority
Defenders should prioritize verifying exposure of Tourmaster versions 5.4.5 and earlier, and assess the need for updates or mitigations.
Recommended defensive actions
- Verify Tourmaster version and assess exposure
- Review and apply updates or mitigations as necessary
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with the primary source being Patchstack. Further verification of affected versions and potential impacts is required.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-69133 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-69133
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-69133 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-69133
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.