CVE-2025-62774Low· 3.1▾ SunlitOn Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2015-8851High· 7.5node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.
CVE-2025-67504Critical· 9.1WBCE CMS is a content management system
CVE-2025-66565Critical· 9.8Fiber Utils is a collection of common functions created for Fiber
CVE-2025-14261High· 7.1The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.
CVE-2025-14972None* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability.
CVE-2025-15629High· 7.5A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation.…