CVE-2025-63226

MEDIUM

Sencore SMP100 - Session Hijacking

Title source: llm
STIX 2.1

Description

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

Scores

CVSS v3 5.7
EPSS 0.0003
EPSS Percentile 7.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (3)
sencore/decoder-ccv2_firmware 60.1.4
sencore/en2sdi-2hd_firmware 60.1.29
sencore/smp100_firmware 4.2.160
Published Nov 18, 2025
Tracked Since Feb 18, 2026