Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/joelczk/cve-2025-48461
IoT SecurityVulnerability AnalysisExploitationWeb SecurityPenetration TestingAuthentication
GitHubjoelczk/cve-2025-48461

CVE-2025-48461

Technical disclosure of a predictable session cookie vulnerability (CVE-2025-48461) in Advantech WISE-4060 IoT portal, enabling bruteforce authentication bypass for admin access.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-48461

Predictable session cookies that can be bruteforced to gain unauthorized access to Advantech WISE portal

Summary

During examination of Advantech WISE-4060 web portal, I have discovered that the session cookies used to authenticate to the web portal follows the pattern 60D01EXXXXX. This allows any unauthorized attacker to generate all possible permutations of all the session cookies and carry out a bruteforce attack against the portal to find a valid session cookie used to authenticate to the web portal.

This vulnerability was discovered during SPIRICYBER-24 IoT/ OT Hackathon organized by CSA(Cybersecurity Agency of Singapore)

Impact

Any unauthorized user is able to authenticate as an admin user and modify settings/firmware for Advantech WISE-4060

References

https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/

https://www.cve.org/CVERecord?id=CVE-2025-48461

Timeline

  • 2024-08-10: Report submitted to SpiritCyber IoT Hackathon triage team
  • 2024-08-20: Report accepted by triage team
  • 2025-06-17: CSA SingCert assigns CVE-2025-48461
  • 2025-06-24: Public disclosure
Download Tool