---
id: CVE-2025-15135
title: >-
  A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to
  3.0.0
summary: >-
  A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to
  3.0.0. This impacts the function tryAuthenticateWithCookies of the file
  AuthenticationInterceptor.java of the component Cookie Handler. Executing
  manipulation ca…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
published: '2025-12-28'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T08:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15135'
references:
  - url: 'https://github.com/joey-zhou/xiaozhi-esp32-server-java/issues/143'
    label: cna@vuldb.com
  - url: >-
      https://github.com/joey-zhou/xiaozhi-esp32-server-java/issues/143#issue-3722315701
    label: cna@vuldb.com
  - url: >-
      https://github.com/joey-zhou/xiaozhi-esp32-server-java/issues/143#issuecomment-3666534810
    label: cna@vuldb.com
  - url: 'https://github.com/joey-zhou/xiaozhi-esp32-server-java/releases/tag/v4.0.0'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338513'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338513'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.713990'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00331
epssPercentile: 0.24085
ingestedAt: '2026-10-06T08:50:17.384Z'
---

## Overview

A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file AuthenticationInterceptor.java of the component Cookie Handler. Executing manipulation can lead to improper authentication. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. Upgrading to version 4.0.0 will fix this issue. It is recommended to upgrade the affected component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
