CVE-2025-15135
joey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookies improper authentication
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.3EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
28 dez 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file AuthenticationInterceptor.java of the component Cookie Handler. Executing manipulation can lead to improper authentication. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. Upgrading to version 4.0.0 will fix this issue. It is recommended to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
joey-zhou · xiaozhi-esp32-server-javaReferências
https://github.com/joey-zhou/xiaozhi-esp32-server-java/issues/143https://github.com/joey-zhou/xiaozhi-esp32-server-java/issues/143#issue-3722315701https://github.com/joey-zhou/xiaozhi-esp32-server-java/issues/143#issuecomment-3666534810https://github.com/joey-zhou/xiaozhi-esp32-server-java/releases/tag/v4.0.0https://vuldb.com/?ctiid.338513https://vuldb.com/?id.338513https://vuldb.com/?submit.713990