On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
References