PT-2025-47524 · Gatesair · Lx600+4
Published
2025-11-19
·
Updated
2025-11-21
·
CVE-2025-63212
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GatesAir Flexiva-LX versions 1.0.13 and 2.0
GatesAir Flexiva-LX models LX100, LX300, LX600, and LX1000
Description
The GatesAir Flexiva-LX devices are affected by an issue where sensitive session identifiers (
sid) are exposed in a publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions. This requires the legitimate administrator to have previously closed the browser window without logging out.Recommendations
Update GatesAir Flexiva-LX version 1.0.13 to a newer version.
Update GatesAir Flexiva-LX version 2.0 to a newer version.
Ensure administrators fully log out of the system instead of simply closing the browser window.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flexiva-Lx
Lx100
Lx1000
Lx300
Lx600