CVE-2025-0479
HIGHCP Plus CP-XR-DE21-S Router >=DE21_S_india_hx806_1.057.043_0023 - Sensitive Cookie Without 'HttpOnly' Flag
Title source: llmDescription
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and compromise the targeted system.
References (1)
Core 1
Core References
Various Sources third-party-advisory
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0005
Scores
CVSS v4
8.6
EPSS
0.0040
EPSS Percentile
32.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-1004
CWE-614
Status
published
Products (1)
CP Plus/CP-XR-DE21-S Router
DE21_S_india_hx806_1.057.043_0023
Published
Jan 20, 2025
Tracked Since
Feb 18, 2026