CVE-2025-64386
HIJACKING OF THE TOKEN AND GAINING ACCESS
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.7EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
31 oct 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The
equipment grants a JWT token for each connection in the timeline, but during an
active valid session, a hijacking of the token can be done. This will allow an
attacker with the token modify parameters of security, access or even steal the
session without
the legitimate and active session detecting it. The web server allows the
attacker to reuse an old session JWT token while the legitimate session is
active.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Circutor · TCPRS1plus¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →