
Technical disclosure of a predictable session cookie vulnerability (CVE-2025-48461) in Advantech WISE-4060 IoT portal, enabling bruteforce authentication bypass for admin access.
Predictable session cookies that can be bruteforced to gain unauthorized access to Advantech WISE portal
During examination of Advantech WISE-4060 web portal, I have discovered that the session cookies used to authenticate to the web portal follows the pattern 60D01EXXXXX. This allows any unauthorized attacker to generate all possible permutations of all the session cookies and carry out a bruteforce attack against the portal to find a valid session cookie used to authenticate to the web portal.
This vulnerability was discovered during SPIRICYBER-24 IoT/ OT Hackathon organized by CSA(Cybersecurity Agency of Singapore)
Any unauthorized user is able to authenticate as an admin user and modify settings/firmware for Advantech WISE-4060
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/
https://www.cve.org/CVERecord?id=CVE-2025-48461