CVE-2025-3495
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 16, 2025
CWE ID 338
Summary
CVE-2025-3495 is a vulnerability affecting Delta Electronics COMMGR versions 1 and 2. The issue lies in the generation of session IDs, which are not sufficiently randomized (CWE-338). An attacker can exploit this weakness to brute force valid session IDs and gain unauthorized access to the system, potentially leading to code execution. This vulnerability poses a significant risk and requires immediate attention for mitigation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.