CVE-2025-63206CRITICAL 9.8EPSS p37.8%
CVE-2025-63206CVE-2025-63206
Description
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.48% probability of exploitation · percentile 37.8% · 2026-06-18T12:00:27Z |
| Published | 2025-11-19 |
| Last modified | 2025-12-31 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Authentication for Critical Functioncwe-306 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.