Back

MEDIUM

Weak Session Cookie Entropy

Published Jun 24, 2025

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

Affected products

Remediation

Vendor solution

This vulnerability can be mitigated by enabling the Security Mode, an existing configuration feature available in previous firmware versions. Security Mode restricts access to unsecured web interfaces and disables unnecessary services to reduce attack surfaces. Users and administrators of affected products are strongly advised to enable Security Mode immediately after configuration.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CSA
Published Jun 24, 2025
Updated Jun 25, 2025
Reserved May 22, 2025

CISA Vulnrichment

Updated Jun 24, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner CSA
Published Jun 24, 2025
Updated Jun 25, 2025

GitHub

No data