Session ID Vulnerability in Delta Electronics COMMGR Product
CVE-2025-3495
9.8CRITICAL
What is CVE-2025-3495?
Delta Electronics COMMGR versions 1 and 2 are susceptible to a vulnerability where session IDs are generated using values that are not sufficiently randomized. This flaw (CWE-338) enables attackers to easily perform a brute-force attack on the session IDs, potentially allowing them to authenticate as legitimate users and execute arbitrary code on the system.
Affected Version(s)
COMMGR Windows 0