CVE-2026-25072

CRITICAL

XikeStor SKS8310-8X <1.04.B07 - Auth Bypass

Title source: llm
STIX 2.1

Description

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using insufficiently random cookie values and exploit exposed session parameters in URLs to gain unauthorized access to authenticated user sessions.

Scores

CVSS v3 9.8
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-330
Status published
Products (1)
seekswan/zikestor_sks8310-8x_firmware < 1.04.b07
Published Mar 07, 2026
Tracked Since Mar 07, 2026