CVE Explorer
CVE-2025-65212
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file without logging into the device management backend. By reading the corresponding username and self-decrypted MD5 password in the core configuration file, the attacker can directly log in to the backend, thereby bypassing the fr
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-565","description":"CWE-565 Reliance on Cookies without Validation and Integrity Checking","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-565","description":"CWE-565 Reliance on Cookies without Validation and Integrity Checking","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://gist.github.com/a2148001284/bcdda75fc8718454f16a7b9259463719"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/cna/references/1
{"url":"https://github.com/a2148001284/test1/blob/main/%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E5%90%8E%E5%8F%B0%E6%BC%8F%E6%B4%9EEN.md"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dcb4b777f1fe2e8cfa0bcd144f8359e70a455991ac400933efcd5f99a13e14c · sha256:59925d513d666207… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.