Authentication Cookie Vulnerability in Tenda AC15 Router
CVE-2025-63666

9.8CRITICAL

Key Information:

Vendor

Tenda

Vendor
CVE Published:
12 November 2025

What is CVE-2025-63666?

The Tenda AC15 router model v15.03.05.18_multi has a significant vulnerability linked to its authentication cookie. This flaw reveals the account password hash to the client and employs a short, low-entropy suffix as the session identifier. An attacker with access to the network or the capability to execute JavaScript in the victim's browser can exploit this weakness by stealing the authentication cookie. Once acquired, the attacker can replay the cookie to gain unauthorized access to restricted resources, potentially compromising sensitive user information.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-63666 : Authentication Cookie Vulnerability in Tenda AC15 Router