Description
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.
Published: 2025-04-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Users are recommended to download and upgrade to COMMGR v2.10.0 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11466 Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.
History

Wed, 16 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
Description Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.
Title COMMGR - Insufficient Randomization Authentication Bypass
Weaknesses CWE-338
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2025-08-19T00:11:36.662Z

Reserved: 2025-04-10T06:21:03.795Z

Link: CVE-2025-3495

cve-icon Vulnrichment

Updated: 2025-04-16T14:23:01.695Z

cve-icon NVD

Status : Deferred

Published: 2025-04-16T03:15:17.530

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-3495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses