The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal the session without the legitimate and active session detecting it. The web server allows the attacker to reuse an old session JWT token while the legitimate session is active.
History

Mon, 03 Nov 2025 16:00:00 +0000


Mon, 03 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Circutor
Circutor tcprs1plus
Vendors & Products Circutor
Circutor tcprs1plus

Fri, 31 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Description The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol. The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal the session without the legitimate and active session detecting it. The web server allows the attacker to reuse an old session JWT token while the legitimate session is active.
Title EXCHANGE OF SENSITIVE INFORMATION IN CLEAR TEXT HIJACKING OF THE TOKEN AND GAINING ACCESS
Weaknesses CWE-319 CWE-613
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:L/SA:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Fri, 31 Oct 2025 14:00:00 +0000

Type Values Removed Values Added
Description The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.
Title EXCHANGE OF SENSITIVE INFORMATION IN CLEAR TEXT
Weaknesses CWE-319
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:L/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: S21sec

Published: 2025-10-31T13:42:32.743Z

Updated: 2025-11-03T15:51:03.421Z

Reserved: 2025-10-31T13:13:35.299Z

Link: CVE-2025-64386

cve-icon Vulnrichment

Updated: 2025-10-31T17:48:26.777Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-31T14:16:13.510

Modified: 2025-11-04T15:41:31.450

Link: CVE-2025-64386

cve-icon Redhat

No data.