Exploitation Summary
EIP tracks 2 public exploits for CVE-2025-60425. PoCs published by adminlove520, aakashtyal.
AI-analyzed exploit summary The repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and functional code.
Description
Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.
Exploits (2)
The repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and functional code.
The repository describes a session persistence vulnerability in Nagios Fusion (CVE-2025-60425) where enabling 2FA fails to invalidate existing sessions, allowing unauthorized access. It includes details on affected versions, mitigation, and disclosure timeline.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L