CVE-2025-63226

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sencore:decoder-ccv2_firmware:60.1.4:*:*:*:*:*:*:*
cpe:2.3:h:sencore:decoder-ccv2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sencore:smp100_firmware:4.2.160:*:*:*:*:*:*:*
cpe:2.3:h:sencore:smp100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sencore:en2sdi-2hd_firmware:60.1.29:*:*:*:*:*:*:*
cpe:2.3:h:sencore:en2sdi-2hd:-:*:*:*:*:*:*:*

History

13 Feb 2026, 16:13

Type Values Removed Values Added
CPE cpe:2.3:o:sencore:smp100_firmware:4.2.160:*:*:*:*:*:*:*
cpe:2.3:o:sencore:en2sdi-2hd_firmware:60.1.29:*:*:*:*:*:*:*
cpe:2.3:o:sencore:decoder-ccv2_firmware:60.1.4:*:*:*:*:*:*:*
cpe:2.3:h:sencore:smp100:-:*:*:*:*:*:*:*
cpe:2.3:h:sencore:decoder-ccv2:-:*:*:*:*:*:*:*
cpe:2.3:h:sencore:en2sdi-2hd:-:*:*:*:*:*:*:*
References () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63226_Sencore_SMP100_Session_Hijacking - () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63226_Sencore_SMP100_Session_Hijacking - Third Party Advisory
References () https://www.sencore.com/ - () https://www.sencore.com/ - Product
First Time Sencore smp100
Sencore en2sdi-2hd
Sencore decoder-ccv2
Sencore smp100 Firmware
Sencore
Sencore en2sdi-2hd Firmware
Sencore decoder-ccv2 Firmware

19 Nov 2025, 19:15

Type Values Removed Values Added
CWE CWE-613
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.7

18 Nov 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 20:15

Updated : 2026-02-13 16:13


NVD link : CVE-2025-63226

Mitre link : CVE-2025-63226

CVE.ORG link : CVE-2025-63226


JSON object : View

Products Affected

sencore

  • smp100_firmware
  • en2sdi-2hd
  • decoder-ccv2
  • en2sdi-2hd_firmware
  • smp100
  • decoder-ccv2_firmware
CWE
CWE-613

Insufficient Session Expiration