Description
On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
Problem types
CWE-305 Authentication Bypass by Primary Weakness
Product status
Any version
References
seclists.org/fulldisclosure/2025/Oct/10
blog.nullvoid.me/posts/mercku-exploits/