# CVE-2025-58079

## Summary

- **CVE ID:** CVE-2025-58079
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-424
- **Published:** Oct 16, 2025
- **Last Modified:** Mar 13, 2026

## Description

Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.

## Affected Products

- NEOJAPAN Inc. — desknet's NEO (V4.0R1.0 to V9.0R2.0)

## References

- [CNA](https://www.desknets.com/neo/support/mainte/17475/)
- [CNA](https://jvn.jp/en/jp/JVN90757550/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._