216.73.217.174

CVE-2025-48461

· Published 24/06/2025 03:15 · Modified 25/06/2025 14:15

Labels: CVE-2025-48461 2025-06-245f57b9bf-260d-4433-bf07-b6a79e9bb7d4CVE-2025-48461CWE-341

Essential information

Published
24/06/2025 03:15
Modified
25/06/2025 14:15
Author
Creator
CVSS
5.0 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / * cpe:2.3:a:*:*:*:*:*:*:*:*:*:*:*

References