CVE-2025-48461

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4060lan:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4050lan:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4010lan:-:*:*:*:*:*:*:*

History

09 Jul 2025, 15:02

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 03:15

Updated : 2025-07-09 15:02


NVD link : CVE-2025-48461

Mitre link : CVE-2025-48461

CVE.ORG link : CVE-2025-48461


JSON object : View

Products Affected

advantech

  • wise-4010lan_firmware
  • wise-4060lan
  • wise-4060lan_firmware
  • wise-4050lan_firmware
  • wise-4050lan
  • wise-4010lan
CWE
CWE-341

Predictable from Observable State