CVE-2025-63206: Critical severity Dasan DS2924 vulnerability
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63206?
The severity of CVE-2025-63206 is considered high due to the potential for authentication bypass and escalated privileges.
How do I fix CVE-2025-63206?
To fix CVE-2025-63206, update the firmware of the Dasan Switch DS2924 to a version later than 1.02.00.
What impact does CVE-2025-63206 have on my network security?
CVE-2025-63206 can significantly compromise network security by enabling unauthorized access and control over the switch.
Is my device vulnerable to CVE-2025-63206?
If you are using Dasan Switch DS2924 firmware versions 1.01.18 or 1.02.00, your device is vulnerable to CVE-2025-63206.
What is the main cause of CVE-2025-63206?
CVE-2025-63206 is primarily caused by an authentication bypass vulnerability within the web-based interface of the affected Dasan switch.