CVE-2025-2859

CRITICAL

Arteche Satech BCU Firmware - Session Hijacking via Cookie Capture

Title source: llm
STIX 2.1

Description

An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.

Scores

CVSS v3 9.8
EPSS 0.0038
EPSS Percentile 29.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
arteche/satech_bcu_firmware 2.1.3
Published Mar 28, 2025
Tracked Since Feb 18, 2026