An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
References
| Link | Resource |
|---|---|
| http://dasansmc.com/ | Broken Link |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63206_Dasan%20Switch%20DS2924%20Authentication%20Bypass | Exploit Third Party Advisory |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63206_Dasan%20Switch%20DS2924%20Authentication%20Bypass | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
31 Dec 2025, 14:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://dasansmc.com/ - Broken Link | |
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63206_Dasan%20Switch%20DS2924%20Authentication%20Bypass - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:o:dasannetworks:ds2924_firmware:1.01.18:*:*:*:*:*:*:* cpe:2.3:o:dasannetworks:ds2924_firmware:1.02.00:*:*:*:*:*:*:* cpe:2.3:h:dasannetworks:ds2924:-:*:*:*:*:*:*:* |
|
| First Time |
Dasannetworks ds2924 Firmware
Dasannetworks ds2924 Dasannetworks |
20 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-306 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63206_Dasan%20Switch%20DS2924%20Authentication%20Bypass - |
19 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 18:15
Updated : 2025-12-31 14:09
NVD link : CVE-2025-63206
Mitre link : CVE-2025-63206
CVE.ORG link : CVE-2025-63206
JSON object : View
Products Affected
dasannetworks
- ds2924
- ds2924_firmware
CWE
CWE-306
Missing Authentication for Critical Function
