CVE-2021-47706
HIGHCOMMAX Biometric Access Control System 1.0.0 - Auth Bypass
Title source: llmDescription
COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.
Exploits (1)
References (5)
Scores
CVSS v4
8.7
EPSS
0.0047
EPSS Percentile
64.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-565
Status
published
Products (1)
COMMAX Co., Ltd./COMMAX Biometric Access Control System
1.0.0
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026