9.8
CVE-2025-63206
- EPSS 0.18%
- Veröffentlicht 19.11.2025 00:00:00
- Zuletzt bearbeitet 31.12.2025 14:09:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dasannetworks ≫ Ds2924 Firmware Version1.01.18
Dasannetworks ≫ Ds2924 Firmware Version1.02.00
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.392 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.