PT-2025-17327 · Elber · Elber Reble310

·

CVE-2025-28238

·

Published

2025-04-18

·

Updated

2025-04-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elber REBLE310 Firmware version 5.5.1.R
Description The issue is related to improper session management, which allows attackers to execute a session hijacking attack. This can be exploited in the Elber REBLE310 equipment with the model number REBLE310/RX10/4ASI.
Recommendations For Elber REBLE310 Firmware version 5.5.1.R, update to a newer version that addresses the improper session management issue to prevent session hijacking attacks. As a temporary workaround, consider restricting access to sensitive sessions and implementing additional security measures to minimize the risk of exploitation.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-28238

Affected Products

Elber Reble310