MEDIUM · 6.5

CVE-2025-63212

GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log...

Vulnerability Description

GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GatesairFlexiva Lx100 Firmware1.0.13
GatesairFlexiva Lx100-
GatesairFlexiva Lx300 Firmware1.0.13
GatesairFlexiva Lx300-
GatesairFlexiva Lx600 Firmware1.0.13
GatesairFlexiva Lx600-
GatesairFlexiva Lx1000 Firmware1.0.13
GatesairFlexiva Lx1000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-63212?

CVE-2025-63212 is a vulnerability with a CVSS score of 6.5 (MEDIUM). GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log...

How severe is CVE-2025-63212?

CVE-2025-63212 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-63212?

Check the references section above for vendor advisories and patch information. Affected products include: Gatesair Flexiva Lx100 Firmware, Gatesair Flexiva Lx100, Gatesair Flexiva Lx300 Firmware, Gatesair Flexiva Lx300, Gatesair Flexiva Lx600 Firmware.