CVE-2025-63666
Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected resources.
Vendor
Product
CWE
Yayın Tarihi
2025-11-12 15:15:38
Güncelleme
2025-11-17 18:59:20
Source Identifier
cve@mitre.org
KEV Date Added
-