CVE-2025-2859

An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Apr 2025, 13:15

Type Values Removed Values Added
Summary
  • (es) Un atacante con acceso a la red donde se encuentra el dispositivo vulnerable podría capturar tráfico y obtener cookies del usuario, lo que le permitiría robar la sesión activa de un usuario y realizar cambios en el dispositivo vía web, dependiendo de los privilegios obtenidos por el usuario.
Summary (en) An attacker with access to the network where the vulnerable device is located could capture traffic and obtain cookies from the user, allowing them to steal a user's active session and make changes to the device via the web, depending on the privileges obtained by the user. (en) An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.

28 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 14:15

Updated : 2025-04-04 13:15


NVD link : CVE-2025-2859

Mitre link : CVE-2025-2859

CVE.ORG link : CVE-2025-2859


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication