CVE-2025-63212
Estado: AnalizadaMedia (6.5)—
GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 27
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-200
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-63212",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-63212",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-11-20T21:01:41.771788Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2025-11-19T20:15:53.380",
"references": [
{
"url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63212%20_GatesAir%20Flexiva-LX%20Series%20_%20Session%20Hijacking",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.gatesair.com/",
"tags": [
"Product"
],
"source": "cve@mitre.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out."
}
],
"lastModified": "2026-06-17T09:52:56.930",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx100_firmware:1.0.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FAE101C6-1663-4A58-B9A7-41BAFD0B2BA1"
},
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx100_firmware:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F5CE624-254C-472E-8D1D-1C3463281CA0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gatesair:flexiva_lx100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4F1D8D39-E16E-440C-AC90-8060CB2C0EB4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx300_firmware:1.0.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D1F6D30-F5D0-4D5A-890D-F9BBCBBB3C45"
},
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx300_firmware:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A53C617-AA10-46A9-B596-3CBC5D4760D5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gatesair:flexiva_lx300:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9A57C780-A6FD-4C47-A7CC-3F5F09B92B16"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx600_firmware:1.0.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67C103A0-68B1-449B-95AA-12B8467A6588"
},
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx600_firmware:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C78DD920-FF73-4575-AE89-AF6608857C25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gatesair:flexiva_lx600:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4EAAF4DB-9F0D-4401-9560-1C463274EB9C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx1000_firmware:1.0.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EEA61DCA-EAAC-4C60-9070-8AAFF7F2B821"
},
{
"criteria": "cpe:2.3:o:gatesair:flexiva_lx1000_firmware:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B168C928-7586-4AB9-95FB-5D759350AD6F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gatesair:flexiva_lx1000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7882D4C9-E3F8-40B9-BDFC-0216066E7907"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}