nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-48461 CVE-2025-48461
MEDIUM
Weak Session Cookie Entropy
Record summary
CVE-2025-48461 has a selected CVSS score of 5.0 (medium); EIP currently links 1 repository PoC.
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Advantech Wireless Sensing and Equipment (WISE)Browse Advantech / Advantech Wireless Sensing and Equipment (WISE)Default status: unknown | CVE List | A2.01 B00 | affected |
Proofs of concept
1Repository PoCs
GitHubjoelczk/CVE-2025-48461Repository PoCby joelczkStars: 0Not analyzed1 file
References
2csa.gov.sg
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061