CVE-2025-64386 - CVE House
Back to Database
Status published High CVE-2025-64386

HIJACKING OF THE TOKEN AND GAINING ACCESS

Vulnerability Description

The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal the session without the legitimate and active session detecting it. The web server allows the attacker to reuse an old session JWT token while the legitimate session is active.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64386

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Víctor Bello Cuevas
  • Aarón Flecha Menéndez
  • Iván Alonso Álvarez

Affected Vendor

Affected Software

TCPRS1plus
Vulnerable Versions:
1.0.14

Timeline

Official Publish: October 31st, 2025
Last Modified: November 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)