CVE-2025-48463
Estado: AnalizadaBaja (3.1)—
Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses unencrypted HTTP communication, potentially leading to unauthorised access or data tampering.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-312
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-48463",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-48463",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-24T16:38:29.629508Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.1,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
"affectedData": [
{
"vendor": "Advantech",
"product": "Advantech Wireless Sensing and Equipment (WISE)",
"versions": [
{
"status": "affected",
"version": "A2.01 B00"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-06-24T03:15:33.870",
"references": [
{
"url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061",
"tags": [
"Third Party Advisory"
],
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-312"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses unencrypted HTTP communication, potentially leading to unauthorised access or data tampering."
},
{
"lang": "es",
"value": "La explotación exitosa de la vulnerabilidad podría permitir a un atacante interceptar datos y realizar un secuestro de sesión en los datos expuestos, ya que el producto vulnerable utiliza una comunicación HTTP no cifrada, lo que potencialmente conduce a un acceso no autorizado o a la manipulación de datos."
}
],
"lastModified": "2026-06-17T09:29:39.657",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40764D08-8173-4AF3-BB93-249D12A9D07D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:advantech:wise-4060lan:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E7DCE031-021A-47BC-B81C-1B0DCB9EB8F1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9CFD6963-E219-48F1-8BDE-C3D9F6B2091B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:advantech:wise-4050lan:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "72DFF800-1684-4038-BB79-C679DCAF4105"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87715BBD-E9A9-404A-B11E-CFCE0E4CA409"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:advantech:wise-4010lan:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9241107A-6586-475F-AE13-C541F9AE8AE6"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
}