PT-2026-23783 · Xikestor · Xikestor Sks8310-8X Network Switch

Vulncheck

·

Published

2026-03-07

·

Updated

2026-03-12

·

CVE-2026-25072

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XikeStor SKS8310-8X Network Switch firmware versions prior to 1.04.B07
Description The XikeStor SKS8310-8X Network Switch firmware contains a flaw related to session identifiers. A remote attacker can hijack authenticated sessions by predicting session identifiers due to insufficiently random cookie values. The vulnerability is present in the /goform/SetLogin API endpoint and involves exposed session parameters within URLs, allowing unauthorized access to authenticated user sessions.
Recommendations Update the firmware to a version later than 1.04.B07.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2026-25072

Affected Products

Xikestor Sks8310-8X Network Switch