Record summary

CVE-2025-48461 has a selected CVSS score of 5.0 (medium); EIP currently links 1 repository PoC.

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 24, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Advantech Wireless Sensing and Equipment (WISE)

Browse Advantech / Advantech Wireless Sensing and Equipment (WISE)

Default status: unknown

CVE ListA2.01 B00affected

Proofs of concept

1

Repository PoCs

GitHubjoelczk/CVE-2025-48461Repository PoCby joelczkStars: 0Not analyzed1 file

1.1 KiB

GitHub

PoC details

References

2