An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
References
Configurations
No configuration.
History
20 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63206_Dasan%20Switch%20DS2924%20Authentication%20Bypass - | |
| CWE | CWE-306 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
19 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 18:15
Updated : 2025-11-20 17:15
NVD link : CVE-2025-63206
Mitre link : CVE-2025-63206
CVE.ORG link : CVE-2025-63206
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
