CVE-2023-49259
The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.04%
- CWE
- CWE-341
- Published
- 2024-01-12
- Last modified
- 2026-03-13
Affected products
- Hongdian H8951-4G-ESP
Weakness type
Related vulnerabilities
- CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
- CVE-2026-15571 — Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
- CVE-2026-42365 — GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
- CVE-2025-40780 — Cache poisoning due to weak PRNG
- CVE-2025-42925 — Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
- CVE-2024-10141 — jsbroks COCO Annotator Session predictable state
- CVE-2021-4277 — fredsmith utils Filename screenshot_sync predictable state
- CVE-2020-5365 — Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The...