CVE-2025-63666 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the…
Critical CVSS: 9.8

CVE-2025-63666

Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected resources.
Vendor
Tenda
Product
Ac15 Firmware
CWE
CWE-284
Yayın Tarihi
2025-11-12 15:15:38
Güncelleme
2025-11-17 18:59:20
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar