CVE-2025-59101
Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has once successfully logged in. As soon as an authentication request from a certain source IP is successful, the IP address is handled as authenticated. No other session information is stored. Therefore, it is possible to spoof the IP address of a logged-in user to gain access to the Access Manager web interface.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.72%
- CWE
- CWE-291
- Published
- 2026-01-26
- Last modified
- 2026-03-13
Affected products
- dormakaba Access Manager 92xx-k5
- dormakaba Access Manager 92xx-k7
Weakness type
Related vulnerabilities
- CVE-2026-86485 — In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket...
- CVE-2026-3690 — OpenClaw Canvas Authentication Bypass Vulnerability
- CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2025-66602 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation....
- CVE-2025-34202 — Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
- CVE-2024-23309 — The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in...
- CVE-2024-32765 — QTS, QuTS hero
- CVE-2023-7211 — Uniway Router Administrative Web Interface reliance on ip address for authentication