CVE-2025-48461

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4060lan:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4050lan:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4010lan:-:*:*:*:*:*:*:*

History

09 Jul 2025, 15:02

Type Values Removed Values Added
References () https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/ - () https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/ - Third Party Advisory
CPE cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4050lan:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4060lan:-:*:*:*:*:*:*:*
cpe:2.3:h:advantech:wise-4010lan:-:*:*:*:*:*:*:*
First Time Advantech wise-4060lan Firmware
Advantech
Advantech wise-4060lan
Advantech wise-4010lan Firmware
Advantech wise-4010lan
Advantech wise-4050lan Firmware
Advantech wise-4050lan

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) La explotación exitosa de la vulnerabilidad podría permitir a un atacante no autenticado realizar conjeturas por fuerza bruta y tomar el control de la cuenta, ya que las cookies de sesión son predecibles, lo que potencialmente permite a los atacantes obtener acceso de root, administrador o usuario y restablecer contraseñas.

25 Jun 2025, 14:15

Type Values Removed Values Added
CWE CWE-341

24 Jun 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 03:15

Updated : 2025-07-09 15:02


NVD link : CVE-2025-48461

Mitre link : CVE-2025-48461

CVE.ORG link : CVE-2025-48461


JSON object : View

Products Affected

advantech

  • wise-4060lan
  • wise-4010lan
  • wise-4050lan_firmware
  • wise-4010lan_firmware
  • wise-4050lan
  • wise-4060lan_firmware
CWE
CWE-341

Predictable from Observable State