PT-2025-47493 · Dasan · Dasan Switch Ds2924

Hiky8

·

Published

2025-11-19

·

Updated

2025-11-20

·

CVE-2025-63206

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dasan Switch DS2924 versions 1.01.18 and 1.02.00
Description An authentication bypass exists in the web based interface of Dasan Switch DS2924. Successful exploitation allows attackers to gain escalated privileges by storing specially crafted cookies in the web browser.
Recommendations Update firmware to a version that addresses this issue. As a temporary workaround, clear browser cookies after each use of the web interface.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-63206

Affected Products

Dasan Switch Ds2924