6.5
CVE-2025-63212
- EPSS 0.36%
- Veröffentlicht 19.11.2025 00:00:00
- Zuletzt bearbeitet 15.01.2026 18:31:02
- Erkennungen
GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gatesair ≫ Flexiva Lx100 Firmware Version 1.0.13
Gatesair ≫ Flexiva Lx100 Firmware Version 2.0
Gatesair ≫ Flexiva Lx300 Firmware Version 1.0.13
Gatesair ≫ Flexiva Lx300 Firmware Version 2.0
Gatesair ≫ Flexiva Lx600 Firmware Version 1.0.13
Gatesair ≫ Flexiva Lx600 Firmware Version 2.0
Gatesair ≫ Flexiva Lx1000 Firmware Version 1.0.13
Gatesair ≫ Flexiva Lx1000 Firmware Version 2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.289 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://www.gatesair.com/
https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63212%20_GatesAir%20Flexiva-LX%20Series%20_%20Session%20Hijacking