Vulnerability Description
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dasannetworks | Ds2924 Firmware | 1.01.18 |
| Dasannetworks | Ds2924 | - |
Related Weaknesses (CWE)
References
- http://dasansmc.com/Broken Link
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-6320ExploitThird Party Advisory
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-6320ExploitThird Party Advisory
FAQ
What is CVE-2025-63206?
CVE-2025-63206 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted coo...
How severe is CVE-2025-63206?
CVE-2025-63206 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-63206?
Check the references section above for vendor advisories and patch information. Affected products include: Dasannetworks Ds2924 Firmware, Dasannetworks Ds2924.