← All CVEs

CVE-2025-63206

critical · 9.8

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.

9.8
CVSS
0.5%
EPSS (exploit prob.)
44th
EPSS percentile
2025-11-19
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Affected products

VendorProductAffected versions
dasannetworksds2924_firmware1.01.18
dasannetworksds2924_firmware1.02.00
dasannetworksds2924all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-63206