Home
LOW: 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NDefault status
unknown
Any version
affected
Description
On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
Problem types
CWE-305 Authentication Bypass by Primary Weakness
Product status
Any version
References
seclists.org/fulldisclosure/2025/Oct/10
blog.nullvoid.me/posts/mercku-exploits/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.