CVE-2025-63226
Last modified
CVE-2025-63226 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sencore | Decoder-Ccv2 Firmware | 60.1.4 |
| Sencore | Smp100 Firmware | 4.2.160 |
| Sencore | En2sdi-2hd Firmware | 60.1.29 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-63226?
How severe is CVE-2025-63226?
How do I fix CVE-2025-63226?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6322A vulnerability was found in PHPGurukul Pre-School Enrollmen…9.8
- CVE-2025-63220The Sound4 FIRST web-based management interface is vulnerabl…7.2
- CVE-2025-63221The Axel Technology puma devices (firmware versions 0.8.5 to…9.1
- CVE-2025-63223The Axel Technology StreamerMAX MK II devices (firmware vers…9.8
- CVE-2025-63224The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to …10
- CVE-2025-63225The Eurolab ELTS100_UBX device (firmware version ELTS100v1.U…9.8
- CVE-2025-63227The Mozart FM Transmitter web management interface on versio…7.2
- CVE-2025-63228The Mozart FM Transmitter web management interface on versio…9.8
- CVE-2025-63229The Mozart FM Transmitter web management interface on versio…5.4
- CVE-2025-6323A vulnerability was found in PHPGurukul Pre-School Enrollmen…9.8
- CVE-2025-63235In sol commit 373d848 (2024-12-12), the broker does not full…7.5
- CVE-2025-63238A Reflected Cross-Site Scripting (XSS) affects LimeSurvey ve…6.1
Are you affected by CVE-2025-63226?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
