Authentication Cookie Vulnerability in Tenda AC15 Router
CVE-2025-63666
What is CVE-2025-63666?
The Tenda AC15 router model v15.03.05.18_multi has a significant vulnerability linked to its authentication cookie. This flaw reveals the account password hash to the client and employs a short, low-entropy suffix as the session identifier. An attacker with access to the network or the capability to execute JavaScript in the victim's browser can exploit this weakness by stealing the authentication cookie. Once acquired, the attacker can replay the cookie to gain unauthorized access to restricted resources, potentially compromising sensitive user information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved