VulnerabilityAnalyzed
CVE-2025-48461
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and…
MEDIUM 5.0EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.
- CVSS 3.1
- 5.0 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-341
- Affected
- advantech/wise-4060lan firmware · advantech/wise-4050lan firmware · advantech/wise-4010lan firmware
- Source
- 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
References
- https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.