CVE-2025-48461

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.
Configurations

No configuration.

History

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) La explotación exitosa de la vulnerabilidad podría permitir a un atacante no autenticado realizar conjeturas por fuerza bruta y tomar el control de la cuenta, ya que las cookies de sesión son predecibles, lo que potencialmente permite a los atacantes obtener acceso de root, administrador o usuario y restablecer contraseñas.

25 Jun 2025, 14:15

Type Values Removed Values Added
CWE CWE-341

24 Jun 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 03:15

Updated : 2025-06-26 18:58


NVD link : CVE-2025-48461

Mitre link : CVE-2025-48461

CVE.ORG link : CVE-2025-48461


JSON object : View

Products Affected

No product.

CWE
CWE-341

Predictable from Observable State