First published: Wed Apr 16 2025(Updated: )
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.
Credit: 759f5e80-c8e1-4224-bead-956d7b33c98b
Affected Software | Affected Version | How to fix |
---|---|---|
Delta Electronics COMMGR | ||
Delta Electronics COMMGR | ||
Delta Electronics COMMGR |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3495 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2025-3495, update to the latest patched version of Delta Electronics COMMGR that addresses session ID generation.
CVE-2025-3495 affects versions 1 and 2 of Delta Electronics COMMGR.
CVE-2025-3495 is an authentication bypass vulnerability due to insufficient randomization of session IDs.
Yes, CVE-2025-3495 can lead to data compromise as attackers may execute arbitrary code by brute-forcing session IDs.