An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
References
| Link | Resource |
|---|---|
| http://dasansmc.com/ | Broken Link |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63206_Dasan%20Switch%20DS2924%20Authentication%20Bypass | Exploit Third Party Advisory |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63206_Dasan%20Switch%20DS2924%20Authentication%20Bypass | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-11-19 18:15
Updated : 2025-12-31 14:09
NVD link : CVE-2025-63206
Mitre link : CVE-2025-63206
CVE.ORG link : CVE-2025-63206
JSON object : View
Products Affected
dasannetworks
- ds2924
- ds2924_firmware
CWE
CWE-306
Missing Authentication for Critical Function
