CVE Vulnerabilities

CVE-2025-62772

Authentication Bypass by Primary Weakness

Published: Oct 22, 2025 | Modified: Oct 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

References