Description
On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.
Problem types
Product status
Any version
References
seclists.org/fulldisclosure/2025/Oct/10
blog.nullvoid.me/posts/mercku-exploits/