CVE-2025-64386

HIGH

Equipment - Session Hijacking

Title source: llm
STIX 2.1

Description

The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal the session without the legitimate and active session detecting it. The web server allows the attacker to reuse an old session JWT token while the legitimate session is active.

Scores

CVSS v4 7.7
EPSS 0.0004
EPSS Percentile 12.5%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-613
Status published
Products (1)
Circutor/TCPRS1plus 1.0.14
Published Oct 31, 2025
Tracked Since Feb 18, 2026