Vulnerabilities (CVE)

Filtered by vendor Gatesair Subscribe
Filtered by product Flexiva Lx1000
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-63212 1 Gatesair 8 Flexiva Lx100, Flexiva Lx1000, Flexiva Lx1000 Firmware and 5 more 2026-01-15 N/A 6.5 MEDIUM
GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out.