SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-48461

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and…

MEDIUM 5.0EPSS 0.43%

Does this matter?

Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

CVSS 3.1
5.0 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
0.43% probability · 36th percentile
CISA KEV
Not listed
Weakness
CWE-341
Affected
advantech/wise-4060lan firmware · advantech/wise-4050lan firmware · advantech/wise-4010lan firmware
Source
5f57b9bf-260d-4433-bf07-b6a79e9bb7d4

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.